Fetching from the wire…
Public story · 2026-07-11 · high
A symlink trick hides where agents actually write, so approving a safe-looking path can trigger code execution instead.
Why now: The July 11 advisory is unusual for naming six mainstream agents under one flaw instead of a single vendor's disclosure.
A symlink-following flaw, tracked as CWE-61, lets malicious repos push coding agents to write files outside their sandbox, per cybersecuritynews.com. The risk lands on anyone who clones an unfamiliar repo into an agent workspace and reviews it with the agent's help. That's a common workflow, not an edge case.
Six agents are named in the advisory: Amazon Q, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. The trick works because the approval prompt shows a path that looks safe. The agent then follows a symlink planted in the repo and writes somewhere else, so you approve a lie.
Symlink attacks are a known category, older than agent sandboxes themselves. Six separate teams built approval flows that don't resolve the link before showing the destination.
The advisory doesn't say whether fixes have shipped for each of the six agents. It also doesn't say if this has been exploited outside research testing. Until vendors confirm otherwise, the approval screen on these six tools doesn't verify what it claims to.
Each link below shares sources, entities, or timing with this story.
The June 12 release connects Cursor, Claude Code, Windsurf, VS Code, Amazon Q, and Kiro to pipeline, build, log, test, and workflow data over MCP. Agents can reason over CI state, like diagnosing a failing build straight from logs, without copy-paste. MCP is becoming the defau...
Stewardship moved to the Agentic AI Foundation under the Linux Foundation, with 30+ tools reading it natively: Claude Code, Copilot, Cursor, Codex, Gemini CLI, Windsurf, Devin, Aider, Amazon Q (BuildBetter). Claude Code reads AGENTS.md in addition to CLAUDE.md, which stays its...
wanshuiyin/HERO-Anti-OverDefense went from creation to 68 stars in a single day. HERO is Hashing, Edge cases, Rubrics, Overbuild, and the claim is that agent over-engineering isn't diffuse but falls into four recognizable shapes suppressible with a portable prompt contract acr...
The Amazon Q bug is one instance of a 2026 pattern: MCP configuration carried in repositories is now an RCE supply-chain vector, not just untrusted tool output. Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI are all vulnerable to MCP-based auto-launch attacks (Windsurf...
The GTM Co-Founder took #1 with 162 upvotes: a free bundle of Agent Skills that interviews a founder for about 15 minutes, learns the product and market, then walks through a prioritized GTM roadmap covering positioning, first 50 users, launch and pricing. Runs inside Claude C...
Pushary took #2 on July 24 with 380 upvotes selling lock-screen approval: it installs a hook intercepting an agent's tool-use event before execution, checks your permission rules, and pushes anything requiring approval to your phone, where you approve, deny, pick an option, or...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.