CVE-2026-30615: Prompt injection in Windsurf enables RCE via malicious MCP server registration
A prompt injection vulnerability in Windsurf 1.9544.26 lets remote attackers embed malicious instructions in HTML content that the AI coding tool processes, causing it to modify the local MCP configuration and register a malicious MCP STDIO server. This results in arbitrary command execution on the victim system without further user interaction.
Disclosed 15 April 2026 · Record updated 13 September 2026
Impact
Attackers can execute arbitrary commands on behalf of the user, persist malicious MCP configuration changes, and access sensitive information exposed through the application.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30615
