SB2025102394 - Prompt Injection in Windsurf



SB2025102394 - Prompt Injection in Windsurf

Published: October 23, 2025

Security Bulletin ID SB2025102394
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2025-36730)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the prompt injection within filename. A remote attacker can create a file name that will be appended to the user prompt and cause Windsurf to follow its instructions.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.