hacker-news · Crawled Jul 9, 2026
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
3 IoCs 2 CVEs
Read original article ↗
AI Summary
Researchers at Wiz discovered a vulnerability pattern called GhostApproval affecting multiple AI coding assistants, including Amazon Q Developer, Claude Code, and Cursor. The flaw exploits symbolic links (symlinks) to redirect file writes to sensitive system files, such as SSH authorized_keys or shell startup files, bypassing user consent by showing misleading approval prompts. While some vendors have issued fixes, others dispute the severity, and the issue highlights a systemic design weakness in how AI agents handle file operations and user approvals.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 8 techniques
T1005 Data from Local System · Collection T1059 Command and Scripting Interpreter · Execution T1059.003 Windows Command Shell · Execution T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.004 Cloud Account · Discovery T1542.001 System Firmware · Persistence T1548.003 Sudo and Sudo Caching · Privilege Escalation