A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
CVE-2026-30615, published on 15 April 2026, records that a prompt injection vulnerability in Windsurf version 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. The record carries a high base score. It is one of the plainest statements in the public vulnerability record that an injected instruction is a path to code execution.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0026
- Kind
- Injection
- Jurisdiction
- Global
- Last verified
- Added
- The CVE record states that a prompt injection vulnerability in the named version allows remote attackers to execute arbitrary commands on a victim system.
- The record was published on 15 April 2026 and assigned by the central numbering authority rather than the vendor.
- The published vector describes a local attack vector with no privileges and no user interaction required.
- The impact on integrity and availability is rated high on the record.
- The affected product entry carries no structured version range beyond the version named in the description.
Dimension by dimension
5 dimensions, each one stated, silent or open
Identity, Authorization, Human approval, Accountability, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- The record describes a remote attacker reaching the assistant's instruction channel.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
- AuthorizationSilent
- The outcome recorded is arbitrary command execution, so nothing constrained what the instruction could reach.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
- Human approvalSilent
- The published vector records no user interaction as a requirement.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
- AccountabilityStated
- A public CVE record exists with a description, a vector and a score.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
- RevocationOpen
- The record does not establish the fixed version, so the remediation state is not settled here.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
Figures
Every number, with who measured it and when
- 8 CVSS base score
CVSS version 3.1 base score on the CVE record
CVE Program record, CVE-2026-30615, primary source, as of .
What it changes
For a team deploying an agent
This record is useful mainly as an argument you can hand a sceptic: prompt injection against a coding assistant is catalogued in the public vulnerability record as remote command execution, not as a model quirk. Track your assistants' versions the way you track any other software that runs commands, and keep the agent's shell inside a sandbox that cannot reach production credentials.
Sources
What this record was verified against
- CVE Program record, CVE-2026-30615Primary · 15 April 2026
Related
Records that sit beside this one
A widely installed documentation MCP server carried a prompt injection into connected coding agents
Global · verified 15 September 2026
The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
A stranger's issue steered a continuous integration agent into reading the environment that held its own API key
United States · verified 15 September 2026
The research states that the returned environment blob contains the unscrubbed API key.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0026 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve
- MLA
- "A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.