GhostApproval Flaw Exposes AI Coding Assistants to Security Risks
AI coding assistants have become deeply embedded in everyday development workflows. Tools such as Claude Code and Cursor can read and write files and execute commands, with their security models built around the core assumption that they will modify only files within a workspace. Cloud and AI security specialist Wiz disclosed a vulnerability called GhostApproval that uses Unix symbolic links to circumvent this boundary. The flaw undermines developers’ trust in AI assistants and exposes corporate supply chains to a new attack surface.
Wiz publicly disclosed details of GhostApproval in July 2026. Attackers can plant symbolic links in a project and trick an AI assistant into believing it is operating within the workspace when it is actually writing to sensitive files outside it, potentially creating a remote code execution (RCE) risk. Several mainstream products, including Claude Code and Cursor, are affected, but vendors differ over remediation timelines and approaches. With no common protection standard yet in place, developers must continue checking projects themselves for suspicious links in the near term.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.