Get a Quote

Windsurf App Security Audit - Harden What the Agent Built

Windsurf's agentic editor lets Cascade take large, multi-step actions across your codebase - creating files, running terminal commands, calling MCP tools. The more autonomy the agent has, the more a human needs to check both what it built and how it's permissioned.

Run a free 30-second scan Book an audit
What Windsurf is

An agentic IDE built around Cascade, now owned by Cognition

Windsurf is a VS Code fork built around Cascade, an agentic assistant that indexes your codebase, plans multi-step tasks, and executes them directly - creating and editing files, running terminal commands, and calling MCP tools, iterating on failures on its own. Windsurf started life as Codeium; after a chaotic July 2025 that saw OpenAI's acquisition talks collapse and Google DeepMind hire away the CEO and co-founder in a licensing deal, Cognition (maker of Devin) acquired the rest of the company within 72 hours - codebase, brand, staff, and enterprise contracts. It now ships as numbered "Wave" releases and is integrated with Devin.

What we find

What Windsurf-built apps get wrong

The pattern with Windsurf isn't just what Cascade writes - it's what Cascade does on its own while writing it.

1. Indirect prompt injection via project files

Hidden instructions planted in a README, a source comment, or a page Cascade fetches over the web can hijack its next actions - this is the root cause behind several of Windsurf's disclosed CVEs, not a theoretical risk.

We fix it by auditing what content sources Cascade trusts and locking down auto-execution on anything sourced from outside your own repo.

2. Secrets and .env exfiltration via auto-approved tools

Security researcher Johann Rehberger documented that Cascade's read_url_content tool could read and send your .env secrets to an attacker-controlled server without ever asking for confirmation - and that auto-rendered images from untrusted domains could leak data the same way. Some of this worked even with auto-execute turned off.

We fix it by rotating anything that may have been exposed and auditing which tools are allowed to run unattended.

3. Over-broad agent autonomy

Cascade executes tool calls and terminal commands with less verification than the risk warrants - the gap between "the agent can do this" and "the agent should confirm this first" is where the exfiltration and RCE issues below live.

We fix it by scoping exactly which tools and commands can run without a human in the loop.

4. Insecure-by-default generated code

Unvalidated inputs, hardcoded or exposed secrets, outdated dependencies, and broken auth show up in Windsurf output the same way they do across agentic coding tools generally.

We fix it with server-side validation, a real secrets manager, and a dependency audit.

Separate issue

Windsurf's own security posture (not the same thing as your app)

This is about the platform, not the code Cascade writes for you. Windsurf's enterprise posture is genuinely strong on paper: SOC 2 Type II, a FedRAMP High ATO via Palantir FedStart on AWS GovCloud, HIPAA BAA support, and SAML SSO, RBAC, and audit logs across tiers. Zero-data-retention is the default on Teams/Enterprise. The catch, flagged by independent researchers: ZDR governs storage, not transmission - a cloud-hosted Windsurf session still sends your code off-device for inference even with ZDR on. Only Self-Hosted or Hybrid deployment modes keep code entirely on your own infrastructure.

ItemStatus
HIPAA / BAAWindsurf supports signing a BAA, but it is not automatic on free or low tiers - must be arranged for the account.
FedRAMP HighAvailable specifically through the Palantir FedStart / AWS GovCloud SKU - not the same as the standard cloud product. Confirm you're on the authorized SKU before relying on it.
Data transmissionZero-data-retention is default on Teams/Enterprise but only stops storage/training - cloud-hosted sessions still transmit code off your device. Self-Hosted or Hybrid mode is required to keep code fully on-premises.
Windsurf's own CVEs

Vulnerabilities disclosed in Windsurf and Cascade itself

These are flaws in the editor/agent, distinct from anything in the apps it generates - directly relevant to anyone giving Cascade autonomy over a real codebase.

CVESeverityWhat it did
CVE-2025-62353CVSS 9.8 CriticalPath traversal in the codebase_search/write_to_file tools let Cascade read or write files outside the project directory - arbitrary file read/write and credential theft via indirect prompt injection, even with auto-execution disabled. Affected Windsurf 1.12.12 and earlier.
CVE-2026-30615CVSS 8.0 HighAttacker-controlled HTML could trigger an unauthorized edit to the local MCP config and auto-register a malicious MCP server - arbitrary command execution with no further user interaction. Affected Windsurf 1.9544.26; no fix was documented at disclosure.
.env exfiltration (no CVE)-Johann Rehberger found Cascade's auto-approved read_url_content tool could exfiltrate .env secrets without asking, and that untrusted auto-rendered images could leak data via image requests. The vendor took roughly three months to respond.
CVE-2025-65715-A VS Code extension flaw confirmed to also affect Windsurf, part of a broader pattern of IDE-extension exfiltration issues (including the GlassWorm supply-chain campaign) across VS Code-based editors.
How we work

What our Windsurf audit checks

  • Server-side auth on every sensitive route, not just what the UI hides
  • No secrets in .env files, source, or the frontend bundle - and rotated if they may have leaked
  • Which Cascade tools are auto-approved, scoped down to what actually needs to run unattended
  • Untrusted content sources (fetched pages, README files, MCP output) treated as hostile input
  • Windsurf version and MCP configuration checked against current advisories
  • Dependencies audited and inputs validated server-side
FAQ

Common questions about Windsurf security

Is Windsurf-generated code secure?

It carries the same recurring gaps common to agentic coding tools - unvalidated inputs, exposed secrets, broken auth - plus autonomy-specific risks unique to how much Cascade can do on its own. A review covers both the code and the agent's permissions.

Does giving Cascade more autonomy add risk?

Yes - more autonomy means more surface area to review. Several of Windsurf's disclosed CVEs trace directly to auto-approved tools (like read_url_content) or auto-registered MCP servers acting without a confirmation step. We audit both what Cascade built and what it's allowed to do unattended.

Is Windsurf HIPAA compliant?

Windsurf supports signing a BAA, but it's not automatic on free or low tiers. Even with a BAA, zero-data-retention on cloud-hosted plans governs storage, not transmission - regulated workloads generally need Self-Hosted or Hybrid deployment to keep code fully on-premises.

Who owns Windsurf now?

Cognition, the company behind the AI software engineer Devin. Cognition acquired Windsurf's codebase, brand, staff, and enterprise contracts in July 2025, after a three-way split that also saw Google DeepMind license some of the underlying technology and hire away several founders.

What does an audit cost?

The initial scan is free and takes about 30 seconds. A full audit starts at and any fixes we recommend are quoted separately based on what we actually find in your app.

Built it in Windsurf. Let's make sure it's safe to launch.

Free 30-second scan, then a clear list of what needs fixing before real users touch it.

Run a free 30-second scan