Back

MEDIUM

Windsurf Prompt Injection via Filename

Published Oct 14, 2025

Description

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model.

It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tenable
Published Oct 14, 2025
Updated Oct 14, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Oct 14, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a