/00 — boot sequence

Hello.

Article

GhostApproval: Critical Symlink Flaw in Six AI Coding Tools

July 11, 2026•7 min read
ghostapproval ai-security coding-agents vulnerability symlink-attack supply-chain-security

Wiz Research has uncovered GhostApproval, a critical trust-boundary vulnerability affecting six of the most popular AI coding assistants. The flaw exploits a decades-old Unix feature -- symbolic links -- to trick AI coding agents into writing malicious code to sensitive system files outside the project sandbox. Cursor received a CVSS score of 9.8 for its implementation of the vulnerability.

How GhostApproval Works

The GhostApproval technique is deceptively simple. An attacker hosts a malicious repository that contains a symbolic link (symlink) named project_settings.json that silently points to ~/.ssh/authorized_keys on the victim's machine. The repository's README instructs the AI agent to "add a line to project_settings.json." When the agent follows this instruction, it writes through the symlink and the attacker's SSH key lands directly in the authorized keys file.

What makes GhostApproval particularly dangerous is the approval box. The AI assistant asks the developer to approve editing project_settings.json, which looks harmless. But the actual write targets ~/.ssh/authorized_keys. The human is still in the loop, but the loop is showing them the wrong file.

Wiz researcher Maor Dokhanian demonstrated a second variant where the symlink points to ~/.zshrc. The agent modifies the shell startup file, which executes automatically the next time the developer opens a terminal -- no SSH service required.

Affected Tools

ToolStatusCVSSNotes
Amazon Q DeveloperFixed (v1.69.0)7.8Write happens before undo prompt
CursorFixed (v3.0)9.8VHS sandbox bypassed
Google AntigravityFixed (May 2026)PendingCVE assessment underway
Claude CodeSymlink warning addedN/AAnthropic disputes as bug
Augment CodeUnaddressedN/ACompany says "expected behavior"
WindsurfReport pendingN/AWrites before approval dialog

Technical Breakdown

The vulnerability exploits a fundamental gap between what the AI agent resolves internally and what it displays to the user. When an AI coding assistant encounters a symlink, it follows the link using standard filesystem operations. The write lands on the resolved target, but the approval dialog shows only the original symlink path.

Wiz tested all six tools: every one performed the write without adequately warning the user. Some tools are worse than others:

Windsurf writes the file to disk before displaying the Accept and Reject buttons. The prompt is effectively an undo button, not an authorization gate. By the time the developer sees it, the SSH key is already in place.

Augment Code shows no dialog at all. Wiz demonstrated Augment silently reading an AWS credential file that sat outside the project workspace, following a symlink to a file containing fake AWS keys.

Amazon Q Developer writes the SSH key before giving the user an "undo" option. While it identifies the symlink in its output, the damage is done before the developer can intervene.

Claude Code internally detected the symlink during Wiz's testing, noting in its own reasoning that "project_settings.json was actually a zsh configuration file." Yet the approval dialog only named the harmless file -- the resolved path was never shown. Anthropic added a symlink warning to Claude Code v2.1.32 in February 2026 as proactive hardening, but disputes that GhostApproval itself is a vulnerability.

Cursor received the highest CVSS score of 9.8 for CVE-2026-50549. The flaw bypasses Cursor's VHS sandbox entirely. The diff displayed in the UI only showed changes to project_settings.json, not the symlink target.

Vendor Responses

The six vendors are split on how to handle the issue:

AWS patched the flaw in Language Servers for AWS version 1.69.0 in May 2026, tracking it as CVE-2026-xxxxx with CVSS 7.8. The update installs automatically for most users.

Cursor shipped a fix in version 3.0 and credited both Wiz and Cato AI Labs in its advisory for CVE-2026-50549.

Google fixed the issue in Antigravity in May and is assessing CVE issuance.

Anthropic told Wiz the scenario "falls outside of the Claude Code threat model," arguing that the developer chose to trust the repository when starting the session. However, it clarified that the "no comment" response was an automated reply from its triage system.

Augment Code told SC Media the behavior is "expected product behavior and not a vulnerability," adding: "A coding agent by design needs to edit and run code to be useful, which means it operates under your credentials."

Windsurf's report remains pending.

GhostApproval is not the first discovery of its kind. In May 2026, Adversa AI published AgentSymlink, demonstrating the same symlink-and-approval pattern against Claude Code, Cursor, GitHub Copilot, and Grok Build. In June, a separate "Rogue Agent" attack planted AI-agent config files in a Microsoft Azure repository -- when a developer opened the project in Claude Code or Cursor, the payload executed automatically.

The fact that two independent research teams found the same pattern points to a shared design weakness rather than a single vendor's oversight. These AI assistants follow symlinks using ordinary filesystem operations, then request approval based on the path they were given, not the path the write actually lands on.

Mitigation Steps

If you use AI coding assistants, take these steps now:

  1. Update your tools. If you use Amazon Q Developer, update to the latest plugin version (auto-updates apply for most users). If you use Cursor, update to version 3.0 or later.

  2. Run agents with limited file access. Use containers or sandboxes to restrict what the agent can read and write. The VHS sandbox in Cursor was bypassed by GhostApproval, so a container-based isolation layer provides stronger protection.

  3. Inspect unfamiliar repos before trusting them. Before letting an AI agent "set up" a repository, review the README and any hidden config files for suspicious symlink patterns.

  4. Check files outside the project after agent runs. Git status only shows changes inside the project. Manually check timestamps on sensitive files:

    bash
  5. Read the full diff before approving. Look past the file name in the approval dialog. If the tool shows a diff, verify that the path in the diff matches what the agent claims to be editing.

  6. Audit AI agent config files. The GhostApproval pattern extends beyond symlinks. Malicious repos can include .cursorrules, .claude.md, or similar agent configuration files that steer the assistant into unsafe behavior.

Frequently Asked Questions

Q: Is GhostApproval being exploited in the wild? A: Wiz states there is no evidence of active exploitation. The research is a proof of concept. However, the technique is straightforward enough that copycat attacks are likely once the research is widely understood.

Q: Does updating my tool fix the problem completely? A: For tools that shipped fixes (Amazon Q, Cursor, Google Antigravity), the update resolves the symlink display issue. For Claude Code, the symlink warning helps but Anthropic does not consider the full scenario a bug. Augment and Windsurf have not shipped fixes.

Q: What is the difference between GhostApproval and AgentSymlink? A: Both demonstrate the same core flaw: symlinks bypass the approval dialog. AgentSymlink was published by Adversa AI in May 2026. GhostApproval, published by Wiz in July 2026, covers additional tools and provides deeper analysis of the trust boundary gap.

Q: Can this attack target files other than SSH keys and shell configs? A: Yes. Any file the developer can write to is a potential target: GPG keys, AWS credentials at ~/.aws/credentials, npm authentication tokens, git config files, and project environment variables.

Key Takeaways

  • GhostApproval exploits a trust boundary gap in six AI coding assistants using decades-old symlink techniques
  • Three vendors have shipped fixes; two have not; one disputes the classification
  • The core issue is that approval dialogs show the symlink name, not the resolved target
  • Cursor received CVSS 9.8 -- the highest score among affected tools
  • Always use sandboxed/container environments for untrusted repositories
  • Human-in-the-loop only protects you if the loop tells the truth

Conclusion

GhostApproval exposes a fundamental design flaw in how AI coding assistants handle filesystem operations. The trust boundary between what the agent resolves internally and what it communicates to the user is broken. "Human in the loop" is only a safeguard when the loop is honest -- and with GhostApproval, it is not.

As AI coding agents gain more autonomy to read and write files, the industry needs a shared security model that resolves symlinks before prompting for approval, flags writes landing outside the project directory, and never touches disk until the user explicitly consents. Until then, every developer using an AI coding assistant should treat unfamiliar repositories with the same caution they would treat an untrusted binary.


Source: Wiz Research - GhostApproval | The Hacker News | SC Media

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links