Windsurf

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-30615

    Prompt Injection in Windsurf Enables Remote Command Execution

    Last Modified: Apr 17, 2026
    Published: Apr 15, 2026

    CVE-2025-62353

    A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.

    Last Modified: Apr 15, 2026
    Published: Oct 17, 2025

    CVE-2025-36730

    Windsurf Prompt Injection via Filename

    Last Modified: Apr 15, 2026
    Published: Oct 14, 2025
    Items Per Page
    Windsurf Vulnerabilities & Security CVEs | CVE-DB