Skip to content

Hide Navigation Hide TOC

Windsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615) - ATR-2026-00535 (f7b98a15-03ef-567c-b947-fafdb3f61cbc)

Detects CVE-2026-30615: zero-click prompt injection targeting Windsurf IDE (and same-class AI coding assistants). An attacker plants adversarial instructions inside source files, code comments, or Markdown the developer opens — no interaction required. When Windsurf reads the file for context, the injected text is processed as a directive by the underlying LLM, causing arbitrary tool calls. Attack surfaces include HTML/XML comment blocks prefixed with "AI:", JSON blobs with "role":"system", inline SYSTEM override markers, and invisible Unicode-padded directives. Windsurf-specific patterns include its @-mention syntax abused inside comments and annotation markers. CWE-77 (Command Injection via AI directive), MITRE ATLAS AML.T0051.001 (Indirect Prompt Injection).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Windsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615) - ATR-2026-00535 (f7b98a15-03ef-567c-b947-fafdb3f61cbc) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Windsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615) - ATR-2026-00535 (f7b98a15-03ef-567c-b947-fafdb3f61cbc) Agent Threat Rules 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Windsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615) - ATR-2026-00535 (f7b98a15-03ef-567c-b947-fafdb3f61cbc) Agent Threat Rules 1
Obfuscated Files or Information - T1027 (b3d682b6-98f2-4fb0-aa3b-b4df007ca70a) Attack Pattern Windsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615) - ATR-2026-00535 (f7b98a15-03ef-567c-b947-fafdb3f61cbc) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2