Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
The Hacker News
1 month ago

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

By info@thehackernews.com (The Hacker News)

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.