2026-07-09NOTABLEWiz "GhostApproval": malicious repos escape the workspace sandbox of six AI coding assistants via symlink + fake confirmation dialog
GhostApproval
tool · tool:ghostapproval-ai-coding-assistant-symlink
Wiz Research's name for a symlink-following (CWE-61) + confirmation-dialog UI-misrepresentation (CWE-451) vulnerability pattern across six AI coding assistants (Amazon Q Developer, Cursor, Google Antigravity, Augment, Windsurf, Anthropic Claude Code) letting a malicious repository write outside the workspace sandbox; CVE-2026-12958 (AWS), CVE-2026-50549 (Cursor) (Wiz Research, 2026-07-08).
Coverage
2
1 about it · 1 mention · first 2026-07-09 → last 2026-07-11
Latest activity
2026-07-09
Wiz "GhostApproval": malicious repos escape the workspace sandbox of six AI coding assistants via symlink +…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector, finance
Sources cited
5
4 hosts
2026-07-092 appearances2026-07-11
Action items (2)
Do-now tasks recorded on the entries about GhostApproval, newest first. Check the date before acting on an older one.
- Patch AWS language-servers to ≥ 1.69.0 (@aws/lsp-codewhisperer ≥ 0.0.117) and Cursor to ≥ 3.0 now; for Augment and Windsurf, restrict use against untrusted/external repositories until a fix ships.2026-07-09CVE-2026-12958 +1
- Alert on any AI-coding-assistant agent process writing to credential/dotfile paths (~/.ssh/*, shell rc files, cloud-credential files) and on git-clone operations that create symlinks resolving outside the repository root.2026-07-09CVE-2026-12958 +1
Defender insights
What each entry about GhostApproval tells a defender to do, newest first.
Story timeline
Every entry that names GhostApproval, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-07-11'Friendly Fire': prompt injection hijacks AI coding agents' defensive auto-review into remote code execution
- 2026-07-09GhostApproval (CVE-2026-12958, CVE-2026-50549), symlink + confirmation-UI misrepresentation lets a malicious repo write outside six AI coding assistants' workspace sandbox
Hunting pivots
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise: Compromise Software Supply Chain
- Defense ImpairmentFile and Directory Permissions Modification
- Credential AccessUnsecured Credentials: Private Keys
Initial Access TA0001
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary · ATT&CK page ↗
Defense Impairment TA0112
T1222File and Directory Permissions Modification×1
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).
Evidence: 2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary · ATT&CK page ↗
Credential Access TA0006
T1552.004Unsecured Credentials: Private Keys×1
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.
Evidence: 2026-07-09/ghostapproval-ai-coding-assistant-symlink-trust-boundary · ATT&CK page ↗
Entries about GhostApproval (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Anthropic Claude Code CLI×1
- AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.117×1
- Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.0×1
- Friendly Fire (AI Now Institute exploit)×1
- OpenAI Codex CLI×1
Where this entity is cited
Source distribution
- github.com2 (40%)
- ainowinstitute.org1 (20%)
- infosecurity-magazine.com1 (20%)
- wiz.io1 (20%)
All cited sources (5)
- ainowinstitute.orgAI Now Institutehttps://ainowinstitute.org/publications/friendly-fire-exploit-brief
- github.comAWS GitHub Security Advisory (GHSA-6v3r-4p5c-mrp5)https://github.com/aws/language-servers/security/advisories/GHSA-6v3r-4p5c-mrp5
- github.comCursor GitHub Security Advisory (GHSA-3v8f-48vw-3mjx)https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/anthropic-openai-report-exploit/
- wiz.ioWiz Researchhttps://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants