GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions
A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

Key points
- Cybersecurity firm Wiz found a vulnerability pattern, named GhostApproval, affecting six major AI coding assistants as of June 2025.
- The six tools affected are Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf (now called Devin Desktop).
- A booby-trapped code repository could trick the AI tool into reading or writing files outside its permitted area, potentially giving attackers full control of a developer's machine.
- AWS and Google fixed the problem quickly; Cursor also patched promptly; Anthropic had already fixed it before Wiz made contact; Augment and Windsurf acknowledged the report and went quiet.
- The flaw points to a design problem across the whole category of AI coding tools, not a one-off bug from a single vendor.
AI coding assistants are now a standard fixture in software teams. They're also, it turns out, a largely unexamined entry point for attackers.
Wiz published findings this month describing a vulnerability pattern it calls GhostApproval. The attack hides a dangerous action inside an approval request that looks completely innocent to the developer who clicks it.
These tools run inside a sandbox, a walled-off area of a computer where the tool is only supposed to touch files within a specific project folder. Attackers can plant symbolic links inside a code repository. A symbolic link is a shortcut file that quietly points elsewhere. When the AI tool follows that shortcut, it ends up reading or writing a sensitive file it was never meant to touch, such as SSH key files (digital credentials that control server access).
Cato Networks reported the issue earlier this month for Cursor alone. Wiz found it runs across all six tools.
Why didn't the safety check stop this?
The safety check didn't stop it because the tool misrepresented what it was doing. Wiz found that in several cases the AI assistant's internal reasoning correctly identified a dangerous file outside the project boundary. The dialog box shown to the developer described something harmless instead. A developer approved what looked like a routine config edit. The tool then wrote to the SSH key file it had concealed.
This is CWE-451, a recognised flaw category covering UI misrepresentation of critical information, layered on top of the symlink attack. We first covered CWE-451 on 9 July 2026, when the same compound problem surfaced in this context.
Katie Norton, senior research manager for DevSecOps at IDC, was direct. "The safety check people rely on to catch these actions doesn't actually stop anything," she told CSO Online. Risk concentrates around workflows touching external contributors, forked repositories, and third-party dependencies rather than internally written code. Norton also noted that since March 2025, comparable issues have emerged in nearly every major AI coding assistant, with bypasses surfacing within months of each patch.
Should you worry?
Yes, if your team clones repositories from sources it doesn't fully vet.
Noah Kenney, principal consultant at Digital 520, put the design tension plainly. "Many considered human in the loop to be the answer to agent risk, but this report shows that the loop can be fed bad information by the very agent it is supposed to be supervising," he told CSO Online. His practical advice: treat AI coding assistants as privileged software with full filesystem access, not editor plugins. Run them against trusted repositories in isolated environments. Don't rely on the tool's own dialog box as your governance layer.
Justin Greis, CEO of consulting firm Acceligence, argued the pattern is structural. Six vendors independently landed on a similar trust model, which suggests a category-wide design challenge rather than isolated implementation bugs. Once an AI agent becomes an active participant in development, every trust boundary it crosses becomes part of the organisation's attack surface.
If your team uses any of the six affected tools: update now, confirm which version you're running, and be cautious about cloning repositories from unfamiliar sources. The post-mortem that follows a breach here will say a developer approved a routine-looking prompt and handed an attacker the keys to production.



