TECH NEWS
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
A malicious code repository can abuse symbolic links to push several popular AI coding assistants beyond their approved workspace, according to new research from Wiz. The vulnerability pattern, named GhostApproval, affected tools from Amazon, Anthropic, Augment, Cursor, Google, Windsurf, and Cognition, with outcomes including misleading approval prompts to file changes