logo

Critical Cline AI Agent Vulnerability Enables Remote Code Execution Attacks

ID: bc34bd77-7ae9-57c7-a42e-eb5ea3a6264e

STIX ID: report--bc34bd77-7ae9-57c7-a42e-eb5ea3a6264e

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: AnuPriya

...
...

**CVE-2026-44211 — kanban (Cline AI):** A critical (CVSS 9.3) unauthenticated WebSocket flaw in the kanban npm package bundled with Cline AI allows malicious webpages to connect to local endpoints without Origin validation, resulting in real-time workspace data leakage, active agent session enumeration, remote command execution (RCE) via the terminal WebSocket, and silent termination of agent tasks; a proof-of-concept covering macOS, Linux, and Windows was published and no patch was available for versions prior to v2.13.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.