PulseAugur
中
实时 17:21:24
English(EN) Wiz disclosed GhostApproval: a symlink flaw in 6 AI coding assistants. A malicious repo can hijack the human-in-the-loop confirmation dialog to write to ~/.ssh/

GhostApproval漏洞影响6款AI编码助手,绕过安全检查

新披露的GhostApproval漏洞影响了至少六款AI编码助手,可能允许恶意代码绕过安全检查并获得系统访问权限。该漏洞利用符号链接漏洞,诱使用户批准可能写入SSH密钥等敏感文件的操作。虽然AWS、Cursor和Google的一些助手已得到修复,但Anthropic、Augment和Windsurf的其他助手仍然存在漏洞。 AI

影响 此漏洞可能允许攻击者通过AI编码工具获得未经授权的系统访问权限,凸显了增强AI驱动开发环境安全性的必要性。

排序理由 披露AI编码助手产品的安全漏洞。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 3 个来源。 我们如何撰写摘要 →

GhostApproval漏洞影响6款AI编码助手,绕过安全检查

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
披露AI编码助手产品的安全漏洞。
Source corroboration
3 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
92 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.
Coverage growth since scoring
+1 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

完整方法见我们的编辑标准。

报道来源 [3]

  1. Mastodon — fosstodon.org TIER_1 Español(ES) · [email protected] ·

    Wiz 发现 GhostApproval:一种利用符号链接(是的,就是那个 70 年代的 Unix 漏洞)欺骗 Claude Code、Cursor 和 Amazon Q Developer 等 AI 助手的攻击方式

    Wiz descubrió GhostApproval: un ataque que engaña a asistentes de IA como Claude Code, Cursor y Amazon Q Developer usando symlinks (sí, la vuln de Unix de los 70s).El agente ve un archivo local inofensivo, pero el symlink apunta a /etc/passwd o ~/.ssh/authorized_keys. El diálogo …

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    📣🚨 主要AI编码助手中的#GhostApproval符号链接漏洞可能隐藏敏感文件目标、绕过批准检查并启用系统访问

    📣🚨 # GhostApproval symlink vulnerabilities in major AI coding assistants could hide sensitive file targets, bypass approval checks, and enable system access too. Read: https:// hackread.com/ghostapproval-fla ws-ai-coding-tools-outside-workspace/ # CyberSecurity # AI # Vulnerabili…

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Wiz披露GhostApproval:6款AI代码助手存在符号链接漏洞。恶意仓库可劫持人工审核确认对话框,写入~/.ssh/

    Wiz disclosed GhostApproval: a symlink flaw in 6 AI coding assistants. A malicious repo can hijack the human-in-the-loop confirmation dialog to write to ~/.ssh/authorized_keys. AWS, Cursor, and Google patched; Anthropic, Augment, Windsurf have not. https:// go.aintelligencehub.co…