GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
A recent discovery by researchers at Wiz reveals a significant security flaw in six popular AI coding assistants that could allow malicious repositories to run unauthorized code on developers' computers. The flaw, which exploits symlink manipulation, tricks the assistants into editing harmless files that instead target sensitive areas. Affected tools include Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This issue underscores the importance of stringent security measures in AI tools, as even minor oversights can have serious implications for developers' data integrity and overall cybersecurity.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.