Kryptovalutaticker:
sysadmin från Cyber Security News

New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

Guru Baran
Jul 9, 2026 at 05:10
29 Visningar
0 Kommentarer
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass Human-in-the-Loop safety controls and potentially achieve remote code execution on developer machines. Discovered by Wiz researchers, GhostApproval exploits a deceptively simple but deeply impactful technique: symbolic link following (CWE-61). A symlink is a filesystem pointer that makes one path silently resolve to another. While this primitive has been exploited for decades in Docker escapes (CVE-2024-21626), npm package managers...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!