GhostApproval vulnerability found in six AI coding assistants bypassing human-in-the-loop approval safeguards
According to CSO Online, security researchers at Wiz discovered GhostApproval, a vulnerability affecting six leading AI coding assistants including Amazon Q Developer that allows attackers to bypass human-in-the-loop safeguards by misleading approval mechanisms. The vulnerability enables unauthorized code execution by circumventing the human review step designed to prevent malicious agent actions. The flaw demonstrates a gap in agent safety architectures where approval workflows can be manipulated through social engineering of the approval interface itself.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.