CVE 4.6 MEDIUM

Windsurf Prompt Injection via Filename_CVE-2025-36730

4.6 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Description

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model.

It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

Basic Information

ID CVE-2025-36730
Source tenable
Published Oct 14, 2025 at 16:24
Modified Oct 14, 2025 at 19:11

Affected Product

Vendor Windsurf
Product Windsurf
Version 1.10.7
Affected Versions Windsurf Windsurf 1.10.7

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.