VYPR

Windsurft

by Windsurft

CVEs (3)

  • CVE-2025-62353CriOct 17, 2025
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.

  • CVE-2026-30615HigApr 15, 2026
    risk 0.52cvss 8.0epss 0.00

    A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration…

  • CVE-2025-36730MedOct 14, 2025
    risk 0.30cvss epss 0.00

    A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.