CVE-2025-36730

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-10-14 17:15

Updated : 2026-06-17 09:14


NVD link : CVE-2025-36730

Mitre link : CVE-2025-36730

CVE.ORG link : CVE-2025-36730


JSON object : View

Products Affected

No product.

CWE

No CWE.