A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2025-10-17T15:51:17.309Z
Reserved: 2025-10-10T13:18:25.507Z
Link: CVE-2025-62353

Updated: 2025-10-17T15:49:58.635Z

Status : Received
Published: 2025-10-17T16:15:39.150
Modified: 2025-10-17T16:15:39.150
Link: CVE-2025-62353

No data.

No data.