CyberRota Analysis
This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.
CVE
CVE-2025-36730
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Original NVD Description
A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.