A trust-boundary flaw in six code agents shows how a malicious repository can manipulate sandboxed tools, not by breaking the model, but by abusing path handling and approval design.
A newly disclosed trust-boundary flaw shows how repository tricks can push coding assistants past their workspace limits, where a single bad write may become a serious host-level security problem.
Wiz has disclosed GhostApproval, an attack method that uses a decades-old technique to mislead AI coding assistants and test the limits of approval-based security on developer machines.
A symlink-based trick shows how agentic coding tools can be pushed beyond the directory a user thinks they approved.
A symlink flaw pattern called GhostApproval shows how approval prompts in AI coding tools can be fooled into sending writes beyond the intended workspace boundary.