GhostApproval Vulnerability: Six AI Coding Assistants Can Be Tricked by Symbolic Links to Write to Sensitive System Files

In July 2026, Wiz Research disclosed the GhostApproval attack: malicious repositories use symbolic links to trick AI coding assistant approval boxes into displaying harmless filenames, while actually writing to sensitive system paths such as ~/.ssh/authorized_keys. Amazon Q (CVE-2026-12958), Cursor 3.0 (CVE-2026-50549) and Google Antigravity have been patched; Augment and Windsurf have not yet received fixes; Anthropic has denied the existence of the vulnerability. This article sorts out the attack chain, the differences between the six tools, and developer protection suggestions.

Read More