Digest
CRITICAL

GhostApproval Symlink Flaws Allow Malicious Repos to Execute Code in AI Coding Assistants

Wiz researchers discovered ‘GhostApproval’ flaws in six popular AI coding assistants, including Amazon Q Developer and Claude Code. This vulnerability allows a booby-trapped code project to gain control of a developer’s machine. The attack works by tricking the assistant into requesting permission to edit a harmless file, but a symlink redirects the write operation to a sensitive system file, bypassing the human-in-the-loop safety model.

← Back to the feed

Trending Tags