Mark RadarMARK RADAR
EN

GhostApproval Flaw Exposes AI Coding Assistants to Security Risks

1 reports · First detected 2026-07-15 · Last active 2026-07-15

AI coding assistants have become deeply embedded in everyday development workflows. Tools such as Claude Code and Cursor can read and write files and execute commands, with their security models built around the core assumption that they will modify only files within a workspace. Cloud and AI security specialist Wiz disclosed a vulnerability called GhostApproval that uses Unix symbolic links to circumvent this boundary. The flaw undermines developers’ trust in AI assistants and exposes corporate supply chains to a new attack surface.

Wiz publicly disclosed details of GhostApproval in July 2026. Attackers can plant symbolic links in a project and trick an AI assistant into believing it is operating within the workspace when it is actually writing to sensitive files outside it, potentially creating a remote code execution (RCE) risk. Several mainstream products, including Claude Code and Cursor, are affected, but vendors differ over remediation timelines and approaches. With no common protection standard yet in place, developers must continue checking projects themselves for suspicious links in the near term.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)