Bug in top AI coding agents shows that Unix-era security headaches never really die
A “systematic vulnerability pattern” in at least six of the most widely used AI coding assistants can be abused to trick agents into accessing files outside the workspace sandbox, leading to remote code execution on the developer's machine.
Google-owned security biz Wiz found the security gap, which it's named "GhostApproval," and reported it to all six: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor,Google Antigravity, and Windsurf.
Amazon, Cursor, and Google deemed the flaw critical or high-severity, fixed it, and either already issued (AWS and Cursor) a CVE tracker or are in the process of getting that done (Google).
Augment and Windsurf acknowledged the Wiz-submitted vulnerability report, but haven’t patched the issue or warned users.
In the race to ship autonomous features, trust-boundary gaps emerge between users, AI agents, and local filesystems. Classic security principles - like resolving symlinks before acting on paths - cannot...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE