Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-12957
CVE
CVE-2026-12957
View on NVD ↗
Arbitrary Code Execution in Language Servers for AWS
Exploitation IoCs
3
Filename
project_settings.json
Filename
~/.ssh/authorized_keys
Filename
~/.zshrc
MITRE ATT&CK TTPs
4
T1059.003
Windows Command Shell
Execution
T1083
File and Directory Discovery
Discovery
T1087.004
Cloud Account
Discovery
T1542.001
System Firmware
Persistence
Source Articles
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz discovered a vulnerability pattern called GhostApproval affecting multiple AI coding assistants, including Amazon Q Developer, Claude Code, and Cursor. The flaw exploits symbolic links (symlinks) to redirect file writes to sensitive system files, such as SSH authorized_keys or shell startup files, bypassing user consent by showing misleading approval prompts. While some vendors have issued fixes, others dispute the severity, and the issue highlights a systemic design weakness in how AI agents handle file operations and user approvals.
hacker-news
Jul 9, 2026