CVE-2026-30615Disclosure

HIGHCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registration of a malicious MCP STDIO server, resulting in execution of arbitrary commands without further user interaction. Successful exploitation may allow attackers to execute commands on behalf of the user, persist malicious MCP configuration changes, and access sensitive information exposed through the application.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 24 mentions across 18 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 17 signals
  • Disclosure: 11 classified signals
  • General: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-06-19); latest day: 1
  • 24 total mentions across 18 days

Deep dive

Activity timeline24 mentions / 18d
01234Mentions · 2026-04-15: 1Mentions · 2026-04-16: 2Mentions · 2026-04-19: 1Mentions · 2026-04-22: 1Mentions · 2026-04-27: 1Mentions · 2026-05-03: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-05-30: 1Mentions · 2026-06-02: 1Mentions · 2026-06-05: 2Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Mentions · 2026-06-19: 4Mentions · 2026-06-21: 1Mentions · 2026-06-27: 1Mentions · 2026-10-06: 1Mentions · 2026-10-07: 1Exploit Tool / Code · 2026-04-15: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-06-18: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-06-05: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-03: 2Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 3Technical Details · 2026-06-21: 104-1504-1604-1904-2204-2705-0305-1005-1105-3006-0206-0506-1606-1806-1906-2106-2710-0610-07
Signal classification4 categories
Disclosure
1150.0%
General
627.3%
Active Exploitation
418.2%
Patch
14.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
Active Exploitation1
2026-04-162
Disclosure2
2026-04-191
General1
2026-04-221
Active Exploitation1
2026-04-271
Disclosure1
2026-05-032
Disclosure1General1
2026-05-101
Disclosure1
2026-05-111
Active Exploitation1
2026-05-301
Disclosure1
2026-06-021
Disclosure1
2026-06-052
Disclosure1Patch1
2026-06-161
Disclosure1
2026-06-181
Active Exploitation1
2026-06-194
Disclosure2General2
2026-06-211
General1
2026-06-271
General1
Full discourse20 posts
  • ほそいりょすけ@rhosoi
    General

    CVE-2026-30615 ダメだわこんなの、claude code使ってMCP試してる層のPCなんてシークレット保管されまくってるから令和のキンタ◯ウイルス出てくるよ

    Post summary

    The text references CVE-2026-30615 and speculates about a potential virus but provides no concrete technical details, exploits, or remediation information.

    00041277
    2.8K followersView on X
  • Hazem Omier@hazemomier

    Opening a repo is now an execution event. Windsurf CVE-2026-30615: a bad MCP config in the repo runs on open, zero clicks. OX Security found the same STDIO injection across 7000+ MCP servers. Who's actually gating repo-level MCP configs before the IDE loads them? How?

    30010129
    469 followersView on X
  • The Agent Times@TheAgentTimes
    Disclosure

    A zero-click remote code execution vulnerability (CVE-2026-30615, CVSS 8.0) allows silent rewriting of AI coding agents' MCP config files, affecting 12+ tools, and Anthropic, Google, and Microsoft have declined to patch the underlying SDK, calling it spec-conformant behavior. https://t.co/RR1x7HfyZy

    Post summary

    The tweet announces CVE‑2026‑30615, a zero‑click RCE affecting AI coding agent SDKs with CVSS 8.0, but notes vendors have declined to patch, claiming spec‑conformant behavior.

    21010212
    169 followersView on X
  • Shreyansh Sancheti@shrey_sancheti

    MCP's default transport, STDIO, allows arbitrary command injection via config inputs. OX Security scanned 7000+ MCP servers in April, found it everywhere. Windsurf CVE-2026-30615: open a git repo with bad MCP config, zero click RCE. Not one vendor's bug. #MCP #AgentSecurity

    00110206
    163 followersView on X
  • Martin Musiol@musiol_martin
    Disclosure

    Zero user interaction. That's the part of CVE-2026-30615 worth sitting with. Windsurf reads attacker-controlled HTML, rewrites its own MCP config, registers a malicious server, runs code. Cursor, VS Code, Claude Code, Gemini-CLI are vulnerable too — Windsurf just didn't need you to click anything.

    Post summary

    CVE-2026-30615 enables an attacker to deliver malicious HTML to Windsurf (and other applications) that rewrites configuration, registers a server, and executes code without any user interaction.

    10010327
    404 followersView on X
  • SuperTute@supertute_inc
    Disclosure

    MCP's STDIO server model is a security hole by design. LangChain-ChatChat and Windsurf both hit by CVEs (CVSS 8.6, 8.0) via MCP STDIO. Attacker controls the command --> your agent runs it. If you run MCP servers: audit them. Now. CVE-2026-30617 + CVE-2026-30615

    Post summary

    The author highlights that LangChain‑ChatChat and Windsurf are affected by CVEs related to MCP STDIO design, allowing command execution, and recommends auditing MCP servers.

    2000048
    3 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Severity vs Product vs Vector: CVE-2026-30615: Critical (vs Product Windsurf IDE | Vector Zero-click prompt injection → local RCE) CVE-2026-30623: Critical (vs Product LiteLLM | Vector Authenticated RCE via JSON config) CVE-2026-26030: Critical (vs Product Semantic Kernel…

    Post summary

    The note lists three critical CVEs, detailing affected products, severity, and exploit vectors but provides no deeper technical or operational information.

    1000057
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    21:10 UTC: CVE-2026-30615 disclosed. The Agentic Kill Chain: How MCP's Architectural RCE and In-the-Wild Prompt Injection Are Converging Into a New Attack Cl

    Post summary

    The message announces the disclosure of CVE‑2026‑30615, noting a potential confluence of architectural RCE and prompt injection but offers no technical specifics or mitigations.

    1000041
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Affected Products (partial list) Windsurf IDE (CVE-2026-30615, zero-click) LangFlow — direct command injection via admin UI GPT Researcher — admin panel MCP config injection LiteLLM — MCP STDIO transport exposure Flowise — configuration-level injection DocsGPT — MCP…

    Post summary

    The excerpt lists products affected by CVE-2026-30615 and related vulnerabilities, providing some technical details but no PoC, exploit code, active exploitation evidence, or patch information.

    1000063
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Vector 3 — Configuration File Poisoning: The zero-click Windsurf CVE (CVE-2026-30615) exploits this vector. MCP server configurations are stored in JSON files within project directories. An attacker who can write to a project repository — or who can trick a developer into…

    Post summary

    The passage outlines a zero‑click configuration file poisoning vulnerability (CVE‑2026‑30615) in AWS Conductor’s MCP server, noting how JSON config files can be poisoned, but provides no PoC, exploit code, or mitigation details.

    1000049
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The most critical single CVE: CVE-2026-30615 in Windsurf IDE — classified as zero-click. An attacker needs no user interaction. Loading a project that contains a malicious MCP configuration file is sufficient for full code execution.

    Post summary

    The post announces CVE‑2026‑30615 in Windsurf IDE, noting a zero‑click vulnerability that allows full code execution via a malicious MCP file, but does not provide PoC, exploit code, patch information, or evidence of active exploitation.

    1000048
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-30615: TL;DR: Forcepoint's Mayur Sewani catalogued 10 in-the-wild indirect prompt injection IPI payloads actively deployed across malicious web pages. Unit 42 independently documented 22 distinct attacker techniques across real-world telemetry — including the…

    Post summary

    The post indicates that CVE‑2026‑30615 is being actively exploited in the wild, with multiple prompt‑injection payloads and attacker techniques documented by Forcepoint and Unit 42.

    1000034
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six live production platforms were compromised during responsible disclosure testing. LiteLLM (CVE-2026-30623, Critical, patched), Windsurf (CVE-2026-30615, Critical, reported), Bisheng (CVE-2026-33224, Critical, patched), and DocsGPT (CVE-2026-26015, Critical, patched)…

    Post summary

    A responsible‑disclosure test compromised six production platforms, revealing several critical CVEs, some of which have since been patched.

    1000046
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Immediate (0-48h): Patch all MCP-connected platforms against the OX Security CVE list: priority CVE-2026-30615 (zero-click Windsurf), CVE-2026-30623 (LiteLLM authenticated RCE), CVE-2026-26015 (DocsGPT MITM) Block public IP access to all LLM/AI enabler services; restrict…

    Post summary

    The advisory stresses immediate patching and network restrictions for several high‑impact CVEs, emphasizing mitigation rather than exploitation details.

    1000063
    246 followersView on X
  • Danny Livshits@dannylivshits
    Active Exploitation

    OX successfully poisoned 9 of 11 MCP registries with a malicious trial balloon. Confirmed RCE on 6 live production platforms including LiteLLM, LangChain, and IBM LangFlow. Windsurf hit by zero-click prompt injection to local RCE (CVE-2026-30615).

    Post summary

    The text reports that CVE‑2026‑30615 is actively exploited in the wild, with confirmed remote code execution on multiple production platforms through a zero‑click prompt injection vulnerability.

    1000084
    232 followersView on X
  • Sattyam Jain@Sattyamjjain
    General

    CVE-2026-30623 (LiteLLM), CVE-2026-30615 (Windsurf), CVE-2026-30617 (Langchain-Chatchat) all hit the same shape: a tool call resolves to shell. The MCP-STDIO transport doesn't bound it. You bound it, or you get bounded.

    Post summary

    The post lists several CVEs, notes that a tool call can spawn a shell, and offers a simple bounding workaround.

    1000047
    67 followersView on X
  • CaptainAmericaTex@CaptAmericaTx
    Active Exploitation

    @PR0GRAMMERHUM0R context On Apr 7 2026 Anthropic announced Mythos, an AI to find security flaws. On Apr 20, security researches found CVE-2026-30615 remote command exploit in the AI SDK (source:cloudsecurityalliance). On Apr 22, haxors gained access to Mythos by guessing URLs (source:TheGuardian)

    Post summary

    The post reports that Anthropic’s Mythos AI SDK contains a CVE‑2026‑30615 remote command execution flaw, and hackers have already accessed the system by guessing URLs, indicating active exploitation in the wild.

    00010112
    131 followersView on X
  • Cyber Kendra@cyberkendra
    Active Exploitation

    Real-world damage: ✅ Unauthenticated RCE on 915+ public LangFlow servers ✅ Production server takeover on Letta AI via MITM ✅ Flowise hardening bypassed with a single npx trick ✅ Windsurf IDE hijacked via prompt injection — zero clicks needed (CVE-2026-30615)

    Post summary

    The message reports real‑world exploitation of CVE‑2026‑30615, with unauthenticated RCE and server takeovers via simple npx usage and MITM attacks. No patch or PoC is referenced.

    1000075
    1.5K followersView on X
  • CyberTLDR@CyberTLDR
    General

    3/3 Treat repo-carried MCP config as untrusted input. Review .amazonq/mcp.json plus Claude Code, Cursor, and Windsurf configs before trusting a workspace. CVE-2025-59536, CVE-2025-54136, and CVE-2026-30615 show this pattern keeps repeating. #AI #SupplyChain #DevSecOps

    Post summary

    The statement notes that several CVEs (2025-59536, 2025-54136, 2026-30615) expose a repeating vulnerability pattern involving repo-carried MCP configurations across AI tools, but it lacks specific technical or remediation details.

    0000083
    15 followersView on X
  • Justin Kwon@ju571nK
    Disclosure

    AIコーディングエージェントの設定ファイル攻撃、ついに「ゼロクリック」になる(CVE-2026-30615)|Justin https://zenn.dev/ju571n/articles/ai-agent-config-zero-click #zenn

    Post summary

    The post announces the newly disclosed CVE-2026-30615, describing it as a zero-click configuration file attack on an AI coding agent, without providing additional technical or mitigation details.

    0000072
    3 followersView on X

Explore more