The Agent Times[verified]@TheAgentTimesDisclosure
The tweet announces CVE‑2026‑30615, a zero‑click RCE affecting AI coding agent SDKs with CVSS 8.0, but notes vendors have declined to patch, claiming spec‑conformant behavior.
Martin Musiol[verified]@musiol_martinDisclosure
CVE-2026-30615 enables an attacker to deliver malicious HTML to Windsurf (and other applications) that rewrites configuration, registers a server, and executes code without any user interaction.
Lyrie.ai[verified]@lyrie_aiGeneral
The note lists three critical CVEs, detailing affected products, severity, and exploit vectors but provides no deeper technical or operational information.
Lyrie.ai[verified]@lyrie_aiDisclosure
The message announces the disclosure of CVE‑2026‑30615, noting a potential confluence of architectural RCE and prompt injection but offers no technical specifics or mitigations.
Lyrie.ai[verified]@lyrie_aiGeneral
The excerpt lists products affected by CVE-2026-30615 and related vulnerabilities, providing some technical details but no PoC, exploit code, active exploitation evidence, or patch information.
Lyrie.ai[verified]@lyrie_aiGeneral
The passage outlines a zero‑click configuration file poisoning vulnerability (CVE‑2026‑30615) in AWS Conductor’s MCP server, noting how JSON config files can be poisoned, but provides no PoC, exploit code, or mitigation details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces CVE‑2026‑30615 in Windsurf IDE, noting a zero‑click vulnerability that allows full code execution via a malicious MCP file, but does not provide PoC, exploit code, patch information, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The post indicates that CVE‑2026‑30615 is being actively exploited in the wild, with multiple prompt‑injection payloads and attacker techniques documented by Forcepoint and Unit 42.