AI Security Research: Windsurf IDE OAuth 2.0 Vulnerability (CVSS 7.1) Zero-Day vulnerability rese...AI Security Research: Windsurf IDE OAuth 2.0 Vulnerability (CVSS 7.1) Zero-Day vulnerability rese...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
AI Security Research: Windsurf IDE OAuth 2.0 Vulnerability (CVSS 7.1) Zero-Day vulnerability research and responsible disclosure on an AI-powered IDE authentication pipeline During deep-dive protocol analysis of the OAuth 2.0 implicit flow, I identified a critical missing nonce parameter validation [1]. Using manual request manipulation and custom test vectors, I successfully confirmed three severe exploit paths end-to-end:
Session Replay (25/25 Confirmed): Captured tokens re-authenticated unauthorized sessions without validation.
CSRF Attacks (3/3 Confirmed): Unvalidated state parameters allowed forced account state binding.
Session Fixation (5/5 Confirmed): Pre-authentication identifiers remained active post-login.
Severity Rating: Scored CVSS 3.1: 7.1 (High) under standard vulnerability scoring frameworks.
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started