AI Security Research: Windsurf IDE OAuth 2.0 Vulnerability (CVSS 7.1)
Zero-Day vulnerability research and responsible disclosure on an AI-powered IDE authentication pipeline
During deep-dive protocol analysis of the OAuth 2.0 implicit flow, I identified a critical missing nonce parameter validation [1]. Using manual request manipulation and custom test vectors, I successfully confirmed three severe exploit paths end-to-end: