Wiz researchers disclose GhostApproval vulnerability in six AI coding assistants

Wiz security researchers disclosed GhostApproval, a vulnerability affecting Amazon Q Developer and five other major AI coding assistants that allows attackers to bypass human-in-the-loop approval by misleading humans in the approval workflow. The vulnerability demonstrates systematic security gaps in approval mechanisms across multiple coding agent platforms.

Topics

AI securityAWS

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.