CVE-2025-62353: Path Traversal
A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62353?
CVE-2025-62353 is categorized as a critical severity vulnerability due to its ability to allow unauthorized access to local files.
How do I fix CVE-2025-62353?
To mitigate CVE-2025-62353, update to the latest version of Windsurf IDE that addresses this vulnerability.
What types of attacks can exploit CVE-2025-62353?
CVE-2025-62353 can be exploited through path traversal attacks enabling unauthorized reading and writing of files.
Which software versions are affected by CVE-2025-62353?
All versions of Windsurf IDE are affected by CVE-2025-62353.
What types of data can be compromised due to CVE-2025-62353?
CVE-2025-62353 allows threats to read and write arbitrary local files, potentially compromising sensitive data.