Kryptovaluta-ticker:
sysadmin fra Cyber Security News

New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

Guru Baran
Jul 9, 2026 at 05:10
27 Visninger
0 Kommentarer
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass Human-in-the-Loop safety controls and potentially achieve remote code execution on developer machines. Discovered by Wiz researchers, GhostApproval exploits a deceptively simple but deeply impactful technique: symbolic link following (CWE-61). A symlink is a filesystem pointer that makes one path silently resolve to another. While this primitive has been exploited for decades in Docker escapes (CVE-2024-21626), npm package managers...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!