Windsurf's agentic editor lets Cascade take large, multi-step actions across your codebase - creating files, running terminal commands, calling MCP tools. The more autonomy the agent has, the more a human needs to check both what it built and how it's permissioned.
Run a free 30-second scan Book an auditWindsurf is a VS Code fork built around Cascade, an agentic assistant that indexes your codebase, plans multi-step tasks, and executes them directly - creating and editing files, running terminal commands, and calling MCP tools, iterating on failures on its own. Windsurf started life as Codeium; after a chaotic July 2025 that saw OpenAI's acquisition talks collapse and Google DeepMind hire away the CEO and co-founder in a licensing deal, Cognition (maker of Devin) acquired the rest of the company within 72 hours - codebase, brand, staff, and enterprise contracts. It now ships as numbered "Wave" releases and is integrated with Devin.
The pattern with Windsurf isn't just what Cascade writes - it's what Cascade does on its own while writing it.
Hidden instructions planted in a README, a source comment, or a page Cascade fetches over the web can hijack its next actions - this is the root cause behind several of Windsurf's disclosed CVEs, not a theoretical risk.
We fix it by auditing what content sources Cascade trusts and locking down auto-execution on anything sourced from outside your own repo.
Security researcher Johann Rehberger documented that Cascade's read_url_content tool could read and send your .env secrets to an attacker-controlled server without ever asking for confirmation - and that auto-rendered images from untrusted domains could leak data the same way. Some of this worked even with auto-execute turned off.
We fix it by rotating anything that may have been exposed and auditing which tools are allowed to run unattended.
Cascade executes tool calls and terminal commands with less verification than the risk warrants - the gap between "the agent can do this" and "the agent should confirm this first" is where the exfiltration and RCE issues below live.
We fix it by scoping exactly which tools and commands can run without a human in the loop.
Unvalidated inputs, hardcoded or exposed secrets, outdated dependencies, and broken auth show up in Windsurf output the same way they do across agentic coding tools generally.
We fix it with server-side validation, a real secrets manager, and a dependency audit.
This is about the platform, not the code Cascade writes for you. Windsurf's enterprise posture is genuinely strong on paper: SOC 2 Type II, a FedRAMP High ATO via Palantir FedStart on AWS GovCloud, HIPAA BAA support, and SAML SSO, RBAC, and audit logs across tiers. Zero-data-retention is the default on Teams/Enterprise. The catch, flagged by independent researchers: ZDR governs storage, not transmission - a cloud-hosted Windsurf session still sends your code off-device for inference even with ZDR on. Only Self-Hosted or Hybrid deployment modes keep code entirely on your own infrastructure.
| Item | Status |
|---|---|
| HIPAA / BAA | Windsurf supports signing a BAA, but it is not automatic on free or low tiers - must be arranged for the account. |
| FedRAMP High | Available specifically through the Palantir FedStart / AWS GovCloud SKU - not the same as the standard cloud product. Confirm you're on the authorized SKU before relying on it. |
| Data transmission | Zero-data-retention is default on Teams/Enterprise but only stops storage/training - cloud-hosted sessions still transmit code off your device. Self-Hosted or Hybrid mode is required to keep code fully on-premises. |
These are flaws in the editor/agent, distinct from anything in the apps it generates - directly relevant to anyone giving Cascade autonomy over a real codebase.
| CVE | Severity | What it did |
|---|---|---|
| CVE-2025-62353 | CVSS 9.8 Critical | Path traversal in the codebase_search/write_to_file tools let Cascade read or write files outside the project directory - arbitrary file read/write and credential theft via indirect prompt injection, even with auto-execution disabled. Affected Windsurf 1.12.12 and earlier. |
| CVE-2026-30615 | CVSS 8.0 High | Attacker-controlled HTML could trigger an unauthorized edit to the local MCP config and auto-register a malicious MCP server - arbitrary command execution with no further user interaction. Affected Windsurf 1.9544.26; no fix was documented at disclosure. |
| .env exfiltration (no CVE) | - | Johann Rehberger found Cascade's auto-approved read_url_content tool could exfiltrate .env secrets without asking, and that untrusted auto-rendered images could leak data via image requests. The vendor took roughly three months to respond. |
| CVE-2025-65715 | - | A VS Code extension flaw confirmed to also affect Windsurf, part of a broader pattern of IDE-extension exfiltration issues (including the GlassWorm supply-chain campaign) across VS Code-based editors. |
It carries the same recurring gaps common to agentic coding tools - unvalidated inputs, exposed secrets, broken auth - plus autonomy-specific risks unique to how much Cascade can do on its own. A review covers both the code and the agent's permissions.
Yes - more autonomy means more surface area to review. Several of Windsurf's disclosed CVEs trace directly to auto-approved tools (like read_url_content) or auto-registered MCP servers acting without a confirmation step. We audit both what Cascade built and what it's allowed to do unattended.
Windsurf supports signing a BAA, but it's not automatic on free or low tiers. Even with a BAA, zero-data-retention on cloud-hosted plans governs storage, not transmission - regulated workloads generally need Self-Hosted or Hybrid deployment to keep code fully on-premises.
Cognition, the company behind the AI software engineer Devin. Cognition acquired Windsurf's codebase, brand, staff, and enterprise contracts in July 2025, after a three-way split that also saw Google DeepMind license some of the underlying technology and hire away several founders.
The initial scan is free and takes about 30 seconds. A full audit starts at and any fixes we recommend are quoted separately based on what we actually find in your app.
Free 30-second scan, then a clear list of what needs fixing before real users touch it.
Run a free 30-second scan