logo

Cline Kanban WebSocket Vulnerability Enables Malicious Sites to Take Over AI Coding Agents

ID: 228afcf7-5a44-58d7-803c-a8642db52e7a

STIX ID: report--228afcf7-5a44-58d7-803c-a8642db52e7a

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Divya

...
...

Cline's Kanban feature contained a critical WebSocket origin-validation flaw (CVSS 9.7) that allowed any webpage visited by a developer to silently connect to the local Kanban server, extract workspace data (filesystem paths, git branches, agent chat history), hijack the agent terminal to execute shell commands (leading to remote code execution), and terminate agent tasks. Oasis Security disclosed the issue and Cline released a patch in version 0.1.66; developers are advised to update immediately, restrict localhost service exposure, and audit AI development environments for similar local listener weaknesses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.