Vulnerabilities & Exploits · Supply Chain

Approval Boxes Are the New Attack Surface

AI coding assistants can be made to lie about what they are changing, so a human click no longer means the write stayed in the workspace. The broken boundary is the approval screen itself: a repo can point a harmless-looking file name at a sensitive local target and turn routine consent into overwrite access to SSH keys or shell startup files.

Wiz says GhostApproval affects Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, Google Gemini, and Windsurf. Three vendors have shipped fixes, two have not, and Anthropic disputes the finding; Wiz also says the pattern can lead to code execution on the developer machine.

This shifts the issue from a single sandbox-escape claim to a broader trust failure across popular assistants. If the tool can edit files after approval, the user prompt is no longer a reliable gate on filesystem writes.

5 sources · Jul 9

CVE-2026-50549

NVD KEV

CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 0.6% (46th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-07-08

Every edition of this story: Approval Boxes Are the New Attack Surface

More from today