CVE-2025-36730 MEDIUM

CVE-2025-36730: Windsurf Prompt Injection via Filename

Vendor Windsurf
Product Windsurf
Weakness CWE-1427
Published October 14, 2025
Last update October 14, 2025

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

Key dates

02Disclosure timeline

October 14, 2025 CVE published
October 14, 2025 Record updated