What happened
Attacker caused Windsurf to process malicious HTML (via a web view, rendered markdown, or similar vector). The HTML caused unauthorized modification of the MCP server configuration and auto-registration of an attacker-controlled MCP STDIO server, achieving RCE without any user interaction.