GhostApproval vulnerability found in six AI coding assistants bypassing human-in-the-loop approval safeguards

According to CSO Online, security researchers at Wiz discovered GhostApproval, a vulnerability affecting six leading AI coding assistants including Amazon Q Developer that allows attackers to bypass human-in-the-loop safeguards by misleading approval mechanisms. The vulnerability enables unauthorized code execution by circumventing the human review step designed to prevent malicious agent actions. The flaw demonstrates a gap in agent safety architectures where approval workflows can be manipulated through social engineering of the approval interface itself.

Topics

AI securityAgentic AISecurityAgentic loop

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.