GhostApproval: How Wiz Research Found AI Coding Assistants Writing Files Before You Approve Them
Wiz Research uncovers GhostApproval: AI coding assistants pre-emptively executing file modifications before user approval prompts.
What GhostApproval Is
Wiz Research disclosed a systemic vulnerability class affecting six major AI coding assistants, where the agent writes file changes to disk before the user-facing approval or undo dialog is shown. In other words, the approval prompt that looks like a gate is really just a confirmation shown after the write already happened, which means a malicious or manipulated file change can land on disk even if a user never clicks Accept, as long as the assistant reaches that code path.
Affected Assistants
Cursor: assigned CVE-2026-50549, fixed in version 3.0. This is the only assistant in the group with a formal CVE at time of publication.
Windsurf: writes modifications to disk before Accept or Reject controls render, which can enable attacker-supplied SSH key injection via disguised files landing before any user review takes place.
Google Antigravity: the permission dialog displays the symlink path rather than the resolved canonical path, which allows a symlink disguised as a file like project_settings.json to silently redirect writes toward a sensitive location such as an SSH directory. Google is assessing CVE issuance as of publication.
Amazon Q: internally identifies symlink targets correctly, but still proceeds with the write before offering an Undo option, so the correct detection doesn't actually block anything.
Why the Trust Boundary Matters
The core issue isn't a single bug in one product, it's a pattern: several independent teams built approval UI on the assumption that showing a prompt before the user can act on it also means the underlying write hasn't happened yet. In agentic coding tools that operate with real file system access, that assumption breaks the entire safety model, since the "approval" becomes cosmetic rather than a genuine gate.
Remediation
Update affected assistants to patched versions as they ship, starting with Cursor 3.0 or later, which is the one confirmed fix so far. Until a vendor patch is available, avoid running AI coding agents with write access in directories that contain, or could be manipulated to contain, symlinks pointing at sensitive paths such as SSH key directories or credential stores. Review agent action logs for any file writes that occurred outside the expected project directory, particularly around symlinked paths. If your team uses any of the affected assistants in an autonomous or semi-autonomous mode, consider temporarily restricting their file system write scope until a fix is confirmed installed.
Related
This post is part of this week's Security Roundup: SonicWall Zero-Days, Microsoft's Record Patch Tuesday, and the Klue Breach Fallout (Week of July 13, 2026), at colibrisec.org/security-roundup-sonicwall-microsoft-klue-july-13-2026/.