CVE-2026-30615
8.0Windsurf · Windsurf 1
A prompt injection vulnerability in Windsurf 1.9544.26 allows unauthenticated attackers to execute arbitrary commands by manipulating local MCP configurations via malicious HTML content.
Executive summary
A critical prompt injection vulnerability in Windsurf 1.9544.26 enables remote command execution, posing a significant risk of unauthorized system access and persistent configuration modification.
Vulnerability
This is a prompt injection flaw where the application fails to safely process attacker-controlled HTML content, allowing an unauthenticated attacker to inject malicious instructions that manipulate the Model Context Protocol (MCP) configuration.
Business impact
The ability for an attacker to execute arbitrary commands on a victim system represents a high-severity risk to confidentiality, integrity, and availability. With a CVSS score of 8.0, this vulnerability could lead to total compromise of the affected workstation, including the exfiltration of sensitive information and the establishment of persistent backdoors via unauthorized MCP server registrations.
Remediation
Immediate Action: Users should immediately restrict the application from processing untrusted HTML content and monitor vendor channels for the release of a security patch.
Proactive Monitoring: Security teams should review application access logs for unusual MCP configuration changes or unexpected STDIO server registration attempts.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to monitor for suspicious child processes spawned by the Windsurf application and utilize network-level filtering to block access to unauthorized MCP servers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, organizations utilizing Windsurf 1.9544.26 must treat this vulnerability with extreme urgency. Until a formal patch is provided by the vendor, administrators should implement strict input validation and restrict the software's ability to modify system-level configurations to minimize the attack surface.