Skip to content
Proposals/Install Windsurf v3.10.31 to close nested Restri
proposalteamP5Worth a lookWindsurf

Install Windsurf v3.10.31 to close nested Restricted Mode bypass (CVE-2026-81376)

Install Windsurf v3.10.31 so Devin Desktop Restricted Mode blocks nested-object workspace settings, not only dotted keys (CVE-2026-81376). Recent sessions show transcripts immediately; composer attachments and SSH reconnects are fixed. ACP is always on; several Cascade entry points are removed.

Why this loop

v3.10.31 closes CVE-2026-81376: Restricted Mode previously blocked dotted restricted workspace keys but not the same settings written as nested objects. Ship 3.10.31 on every Devin Desktop machine, then strip nested copies of restricted keys so policy cannot be bypassed that way. In the same 3.10.x window, switching back to one of the 10 most recently viewed sessions shows its transcript immediately; dragging Explorer files onto the agent panel or sending an editor selection to chat again adds them to the composer; Remote SSH sessions open after reload or relaunch without a session-locked-by-another-process error, recover the exact transcript on reconnect, and are selectable as saved hosts with status dots. Breaking: ACP is always enabled (toggle gone); Cascade new-agent, annotations, conversation mentions, settings group, automatic Lifeguard checks, Vibe & Replace, Deploy, and workflow commands are removed. Re-authorize MCP (provider opens directly) and relaunch Docker-based registry MCP servers. Do not invent the truncated cloud-session archive line.

Proposed actions

  1. Download and install Windsurf v3.10.31 from https://windsurf.com/changelog#v3-10-31 on every Devin Desktop machine so Restricted Mode blocks restricted workspace settings written as nested objects, not only dotted-form keys (CVE-2026-81376).
  2. Search .vscode/settings.json and *.code-workspace files for restricted keys stored as nested objects (e.g. {"foo": {"bar": value}}) rather than dotted keys (foo.bar); delete or formally allowlist those nested entries so they cannot evade Restricted Mode the way they did before v3.10.31.
  3. After upgrade, switch back to each of your 10 most recently viewed Devin sessions and confirm the transcript appears immediately; drag Explorer files onto the agent panel and send an editor selection to chat so both attach to the composer again (fixed in v3.10.27).
  4. From the Devin Desktop location selector, save Remote SSH agent hosts, then reload or relaunch Windsurf and reopen those sessions — they must connect without a “session is locked by another process” error, recover the exact transcript on reconnect, and show status dots plus a server icon in the sidebar.
  5. Remove automations that call removed Cascade entry points (new-agent option, annotations, conversation mentions, Cascade settings group, automatic Lifeguard checks, Vibe & Replace, Deploy, workflow commands). Do not look for an Enable ACP toggle (ACP is always on). Re-authorize MCP providers so they open directly and relaunch Docker-based MCP servers from the registry.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Cascade agent task

DevAgentRadar → Windsurf Cascade

Goal: analyze and pilot this coding release update in my project.

Context

Assistant: Windsurf Proposal: Install Windsurf v3.10.31 to close nested Restricted Mode bypass (CVE-2026-81376) Summary: Install Windsurf v3.10.31 so Devin Desktop Restricted Mode blocks nested-object workspace settings, not only dotted keys (CVE-2026-81376). Recent sessions show transcripts immediately; composer attachments and SSH reconnects are fixed. ACP is always on; several Cascade entry points are removed. Primary source: https://windsurf.com/changelog#v3-10-31

Why it matters

v3.10.31 closes CVE-2026-81376: Restricted Mode previously blocked dotted restricted workspace keys but not the same settings written as nested objects. Ship 3.10.31 on every Devin Desktop machine, then strip nested copies of restricted keys so policy cannot be bypassed that way. In the same 3.10.x window, switching back to one of the 10 most recently viewed sessions shows its transcript immediately; dragging Explorer files onto the agent panel or sending an editor selection to chat again adds them to the composer; Remote SSH sessions open after reload or relaunch without a session-locked-by-another-process error, recover the exact transcript on reconnect, and are selectable as saved hosts with status dots. Breaking: ACP is always enabled (toggle gone); Cascade new-agent, annotations, conversation mentions, settings group, automatic Lifeguard checks, Vibe & Replace, Deploy, and workflow commands are removed. Re-authorize MCP (provider opens directly) and relaunch Docker-based registry MCP servers. Do not invent the truncated cloud-session archive line.

Suggested actions

  1. Download and install Windsurf v3.10.31 from https://windsurf.com/changelog#v3-10-31 on every Devin Desktop machine so Restricted Mode blocks restricted workspace settings written as nested objects, not only dotted-form keys (CVE-2026-81376).

  2. Search .vscode/settings.json and *.code-workspace files for restricted keys stored as nested objects (e.g. {"foo": {"bar": value}}) rather than dotted keys (foo.bar); delete or formally allowlist those nested entries so they cannot evade Restricted Mode the way they did before v3.10.31.

  3. After upgrade, switch back to each of your 10 most recently viewed Devin sessions and confirm the transcript appears immediately; drag Explorer files onto the agent panel and send an editor selection to chat so both attach to the composer again (fixed in v3.10.27).

  4. From the Devin Desktop location selector, save Remote SSH agent hosts, then reload or relaunch Windsurf and reopen those sessions — they must connect without a “session is locked by another process” error, recover the exact transcript on reconnect, and show status dots plus a server icon in the sidebar.

  5. Remove automations that call removed Cascade entry points (new-agent option, annotations, conversation mentions, Cascade settings group, automatic Lifeguard checks, Vibe & Replace, Deploy, workflow commands). Do not look for an Enable ACP toggle (ACP is always on). Re-authorize MCP providers so they open directly and relaunch Docker-based MCP servers from the registry.

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/windsurf-v3-10-31-install-windsurf-v3-10-31-to-close-nested-restricted-m and mark Applied, Skipped, or Failed. Proposal id: 11a9e636-c2d7-4d5a-8056-1f4f30849760

Instructions:

  • Provide a brief breakdown of potential workflow improvements
  • Propose localized updates without touching unrelated logic
  • Verify changes with relevant tests before concluding

Confirm receipt of task and wait for my instruction to begin.

agentmcpmodelsecuritybreakingRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

Windsurfv3.10.31Sep 16, 2026

v3.10.31

v3.10.31 September 16, 2026 · Restricted Mode blocks restricted workspace settings written in nested object form, not just the dotted form (CVE-2026-81376). · Switching back to one of your 10 most recently viewed sessions shows its transcript immediately. · Download 3.10.31
Verified excerpt — the source's own words

v3.10.31 September 16, 2026

Devin Desktop

  • Restricted Mode blocks restricted workspace settings written in nested object form, not just the dotted form (CVE-2026-81376).
  • Switching back to one of your 10 most recently viewed sessions shows its transcript immediately. Download 3.10.31
Primary source ↗