AnalysisCybersecurityJuly 9, 2026
GhostApproval symlink flaw in AI coding assistants allows code execution

Researchers at Wiz discovered a symlink vulnerability in six popular AI coding assistants that could allow attackers to execute arbitrary code on a developer's system. The flaw, dubbed GhostApproval, tricks the assistant into writing to sensitive files by exploiting symlinks in repositories.
1 source
More stories today
- Work with docs, sheets, and slides in ChatGPT
- Lawmakers prepare AI 'kill switch' bill
- Rivian uses Databricks to deliver monthly AI fleet updates
- Dust co-founder discusses model-agnostic AI platform bet
- How regulated organizations can increase AI code velocity safely