hacker-news · Crawled Jul 9, 2026

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

3 IoCs 2 CVEs
Read original article ↗

AI Summary

Researchers at Wiz discovered a vulnerability pattern called GhostApproval affecting multiple AI coding assistants, including Amazon Q Developer, Claude Code, and Cursor. The flaw exploits symbolic links (symlinks) to redirect file writes to sensitive system files, such as SSH authorized_keys or shell startup files, bypassing user consent by showing misleading approval prompts. While some vendors have issued fixes, others dispute the severity, and the issue highlights a systemic design weakness in how AI agents handle file operations and user approvals.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename project_settings.json Details →
Filename ~/.ssh/authorized_keys Details →
Filename ~/.zshrc Details →

MITRE ATT&CK TTPs 8 techniques