Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registration of a malicious MCP STDIO server, resulting in execution of arbitrary commands without further user interaction. Successful exploitation may allow attackers to execute commands on behalf of the user, persist malicious MCP configuration changes, and access sensitive information exposed through the application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Windsurf 安全漏洞
Vulnerability Description
Windsurf是Windsurf公司的一款AI编程软件。 Windsurf 1.9544.26版本存在安全漏洞,该漏洞源于提示注入,可能导致远程攻击者在受害者系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A