Discussion

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Started by The Hacker News · 09 Jul 2026 07:58 · 20 Views · 0 Replies
Thread Starter #0
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.

The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

Okumaya devam et...

You must be logged in to reply.

0 quotes selected