Skip to content
GhostApproval vulnerability in AI coding agents enables remote code execution

GhostApproval vulnerability in AI coding agents enables remote code execution

Feeds.4Sysops IT News July 8, 2026

A widespread vulnerability pattern named GhostApproval has been discovered in several popular AI coding assistants, including Amazon Q Developer, Cursor, and Google Antigravity. The flaw exploits a classic Unix-era security weakness involving symbolic links (symlinks) to bypass the intended workspace sandbox. By tricking an AI agent into interacting with a malicious repository, attackers can force the tool to read or write sensitive files outside the project directory. Source

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)