CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

GhostApproval Symlink Flaws Let Malicious Repos Execute Code in AI Coding Assistants

July 9, 2026

Security researchers at Wiz have identified a critical vulnerability pattern, dubbed GhostApproval, affecting six popular AI coding assistants. The flaw allows a malicious code repository to trick the assistant into writing to sensitive system files, such as SSH authorized_keys or shell startup scripts, by abusing Unix symbolic links (symlinks). The approval dialog shown to the developer displays the symlink’s name rather than the actual target file, bypassing informed consent. Affected tools include Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Three vendors have released fixes, two are working on patches, and Anthropic disputes the classification. Wiz published the research on July 8, 2026. The attack requires the developer to trust a malicious repository, but the deceptive approval box undermines the human-in-the-loop safeguard. Wiz recommends running agents in sandboxes, reviewing repository files before use, and checking timestamps of critical files after sessions. The same pattern was independently discovered by Adversa AI (SymJack) and Cato AI Labs (DuneSlide), indicating a shared design weakness across multiple AI coding tools.

CVEs: CVE-2026-12958, CVE-2026-50549, CVE-2026-12957, CVE-2026-55200, CVE-2026-46817

Malware: Miasma

Companies: Wiz, Amazon, Anthropic, Augment, Cursor, Google, Windsurf, Adversa AI, Cato AI Labs

Products: Amazon Q Developer, Claude Code, Cursor, Google Antigravity, Windsurf, Augment