GhostApproval is the name of a new class of attacks researchers Wiz that affects six popular AI coding assistants, which can be tricked into executing malicious code on developers’ computers via an old Unix mechanism. The attack exploits symbolic links (symlinks) to bypass the user’s approval process, making them believe they are editing a harmless file, while in fact a sensitive system file is being modified. The findings were published on July 8, 2026 , and have already sparked heated debate in the cybersecurity community.

The tools affected by GhostApproval are: Amazon Q Developer , Anthropic 's Claude Code , Augment , Cursor , Google Antigravity , and Windsurf . These are some of the most widely used AI software development tools, which makes the vulnerability particularly concerning. Of the six vendors, three have already released fixes, two are working on them, while Anthropic disputes that this is even a bug.
See also: Anthropic: Claude Sonnet 4.5 is here with improved coding capabilities
How GhostApproval and symlinks exploitation work
The GhostApproval attack relies on a simple but highly effective mechanism. Wiz researchers created a malicious repository that contains a symlink named project_settings.json, which points to the file ~/.ssh/authorized_keys — the file that controls who can log in to the system via SSH without a password. The README instructs the AI assistant to add “a line” to project_settings.json, which is actually the SSH key , disguised as a harmless setting.
When the developer asks the agent to "set up the workspace" or "follow the README," the agent writes the key via the symlink directly to the SSH file. If the machine is running an SSH service accessible to the attacker, the attacker can connect without a password.
A second variant of the attack targets the ~/.zshrc, which is executed every time a terminal is opened, even eliminating the need for SSH. The problem is not the existence of symlinks — they are an old Unix — but the fact that AI tools do not check them before executing writes.
The most concerning aspect is the bypass of the approval process. In Claude Code, the agent recognized the real target, noting that project_settings.json was “actually a zsh configuration file.” However, the approval window only displayed the innocuous filename. The developer clicks “Accept” thinking they are editing a local configuration file, when in fact they are modifying the shell startup file or SSH keys. Wiz describes this as “informed consent bypass”: the human is involved, but is misled.
See also: Agentjacking: New attack tricks AI coding agents into executing malicious code

GhostApproval: Which tools are most dangerous?
Some tools have even more serious problems. Windsurf writes the file to disk before the “Accept” and “Reject” buttons appear, making the dialog just an undo option — with the key already installed. Augment does n’t display any dialog, and Wiz has been shown to silently read AWS outside of the project. Even tools that display an approval dialog are not safe, as they report the wrong file.
Anthropic’s response stands out from other vendors. The company argues that the scenario falls “outside its threat model”: the developer chose to trust the folder at the start of the session and approved the edit, so the decision is theirs. Anthropic also claims that the symlink in Claude Code was released in early February, before Wiz’s private report, as a routine security enhancement. The question Anthropic’s stance raises is an important one: how far should a coding agent go to protect a developer who has already trusted a malicious repository?
Protection
Beyond vendor fixes, there are practical measures that can reduce risk regardless of the tool used. First, run the agent with limited file access or inside a sandbox or container . Second, check the README and hidden configuration files of a repository before allowing the agent to “configure” it. Third, after working on an unknown repository, check the ~/.ssh/authorized_keys and ~/.zshrc files for unexpected changes. Adopting a principle of least privilege for AI agents is now imperative, especially in enterprise environments where AWS or SSH credentials can lead to much more serious breaches.
See also: SymJack: New attack turns AI coding agents into supply chain weapons

GhostApproval highlights a fundamental challenge in the age of AI coding agents: the speed and automation these tools offer can be a weapon in the hands of malicious actors. As developers increasingly trust AI assistants to perform tasks, transparency in approval windows and control of symlinks should be key security requirements. According to The Hacker News, there is no evidence yet that the method has been used in real attacks, but the publication of the findings significantly increases the risk of exploitation in the near future.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
