AnalysisCybersecurityJuly 9, 2026

GhostApproval symlink flaw in AI coding assistants allows code execution

Researchers at Wiz discovered a symlink vulnerability in six popular AI coding assistants that could allow attackers to execute arbitrary code on a developer's system. The flaw, dubbed GhostApproval, tricks the assistant into writing to sensitive files by exploiting symlinks in repositories.

1 source

More stories today

Open the live feed