← Back to CVEs
CVE-2025-62353
CRITICAL9.8
Description
A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/17/2025
Last Modified10/21/2025
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-22
References
https://hiddenlayer.com/sai_security_advisor/2025-10-windsurf/(6f8de1f0-f67e-45a6-b68f-98777fdb759c)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.