Skip to main content
VerifiedInjection

A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine

CVE-2026-30615, published on 15 April 2026, records that a prompt injection vulnerability in Windsurf version 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. The record carries a high base score. It is one of the plainest statements in the public vulnerability record that an injected instruction is a path to code execution.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0026
Kind
Injection
Jurisdiction
Global
Last verified
Added
  • The CVE record states that a prompt injection vulnerability in the named version allows remote attackers to execute arbitrary commands on a victim system.
  • The record was published on 15 April 2026 and assigned by the central numbering authority rather than the vendor.
  • The published vector describes a local attack vector with no privileges and no user interaction required.
  • The impact on integrity and availability is rated high on the record.
  • The affected product entry carries no structured version range beyond the version named in the description.

Dimension by dimension

5 dimensions, each one stated, silent or open

Identity, Authorization, Human approval, Accountability, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The record describes a remote attacker reaching the assistant's instruction channel.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
AuthorizationSilent
The outcome recorded is arbitrary command execution, so nothing constrained what the instruction could reach.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
Human approvalSilent
The published vector records no user interaction as a requirement.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
AccountabilityStated
A public CVE record exists with a description, a vector and a score.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.
RevocationOpen
The record does not establish the fixed version, so the remediation state is not settled here.CVE Program record, CVE-2026-30615, primary source, 15 April 2026.

Figures

Every number, with who measured it and when

  1. 8 CVSS base score

    CVSS version 3.1 base score on the CVE record

    CVE Program record, CVE-2026-30615, primary source, as of .

What it changes

For a team deploying an agent

This record is useful mainly as an argument you can hand a sceptic: prompt injection against a coding assistant is catalogued in the public vulnerability record as remote command execution, not as a model quirk. Track your assistants' versions the way you track any other software that runs commands, and keep the agent's shell inside a sandbox that cannot reach production credentials.

Sources

What this record was verified against

  1. CVE Program record, CVE-2026-30615Primary · 15 April 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0026 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve
MLA
"A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve.
Chicago
GAGE (Global Academy of Generative-AI Education). "A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0026-windsurf-prompt-injection-remote-command-execution-cve

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.