CVE-2026-50549
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 0.6% (46th percentile).
Vulnerabilities · 67 days ago
AI coding assistants can be made to lie about what they are changing, so a human click no longer means the write stayed in the workspace. The broken boundary is the approval screen itself: a repo can point a harmless-looking file name at a sensitive local target and turn routine consent into overwrite access to SSH keys or shell startup files.
Wiz says GhostApproval affects Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, Google Gemini, and Windsurf. Three vendors have shipped fixes, two have not, and Anthropic disputes the finding; Wiz also says the pattern can lead to code execution on the developer machine.
This shifts the issue from a single sandbox-escape claim to a broader trust failure across popular assistants. If the tool can edit files after approval, the user prompt is no longer a reliable gate on filesystem writes.
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 0.6% (46th percentile).
5 sources covering this story
GhostApproval Flaw Hits Six Major AI Coding Assistants
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
Wiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval.
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Wiz says GhostApproval abuses symlinks so AI coding agents write to SSH keys or shell startup files while showing benign paths.
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
GhostApproval: AI Coding Assistant Trust Boundary Flaw | Wiz Blog
Wiz Research uncovered GhostApproval, a trust boundary flaw affecting leading AI coding assistants that can bypass human approval and enable code execution.
Part of the PlainSec briefing for 2026-07-10