Back Feeds.4Sysops GhostApproval vulnerability in AI coding agents enables remote code execution
A widespread vulnerability pattern named GhostApproval has been discovered in several popular AI coding assistants, including Amazon Q Developer, Cursor, and Google Antigravity. The flaw exploits a classic Unix-era security weakness involving symbolic links (symlinks) to bypass the intended workspace sandbox. By tricking an AI agent into interacting with a malicious repository, attackers can force the tool to read or write sensitive files outside the project directory. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
