Tartışma

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Başlatan The Hacker News · 09 Tem 2026 07:58 · 19 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.

The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi