Security researchers disclosed a systemic vulnerability pattern, dubbed “GhostApproval,” affecting widely used AI coding assistants including Amazon Q Developer, Anthropic’s Claude Code, Google’s Antigravity, Augment, and Windsurf. The flaw combines symbolic-link following in the filesystem with a user-interface misrepresentation bug, letting a malicious repository trick an agent into writing files outside its intended workspace while concealing the true target from the human approval prompt meant to stop destructive actions. In proof-of-concept tests, researchers demonstrated planting SSH keys and modifying shell configuration files without triggering a genuine review, though no real-world exploitation was reported. Amazon and Google shipped fixes; Anthropic disputed the vulnerability classification but added symlink warnings in a later Claude Code release.