PT-2026-33069 · Codeium · Windsurf

Published

2026-04-15

·

Updated

2026-06-02

·

CVE-2026-30615

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windsurf version 1.9544.26
Description A prompt injection issue occurs when the application processes attacker-controlled HTML content. This allows remote attackers to execute arbitrary commands on a victim system without user interaction. The flaw enables unauthorized modification of the local MCP configuration and the automatic registration of a malicious MCP STDIO server. Successful exploitation can lead to command execution on behalf of the user, persistence of malicious configuration changes, and access to sensitive information. Real-world incidents include the hijacking of the Windsurf IDE.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30615

Affected Products

Windsurf