Cline AI Agent Flaw Allows Attackers to Launch RCE Attacks
ID: 2c34120b-0130-5daf-8087-c463f91313ed
STIX ID: report--2c34120b-0130-5daf-8087-c463f91313ed
Feed Name: GBHackers
A critical vulnerability (CVE-2026-44211, CVSS 9.3) in the Cline AI kanban npm package exposes unauthenticated WebSocket endpoints on 127.0.0.1:3484 that perform no Origin validation, enabling a malicious webpage to silently connect and: leak workspace and git data, detect active AI agent sessions, inject arbitrary shell commands for remote code execution via the terminal endpoint, and terminate agent tasks (DoS). A PoC demonstrating the full attack chain was published, the issue affects versions prior to v2.13.0 across macOS/Linux/Windows and major browsers, and recommended mitigations include Origin validation, a startup secret token, and authentication for terminal endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
