logo

9.6 Severity: Critical “Cline” AI Agent Flaw Allows Stealthy RCE via Your Browser

ID: ecc5385c-15ea-579e-8b6d-7ab8c988d720

STIX ID: report--ecc5385c-15ea-579e-8b6d-7ab8c988d720

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

The report discloses CVE-2026-44211, a critical (CVSS 9.6) Cross-Origin WebSocket Hijacking vulnerability in the kanban npm package used by the Cline CLI that allows malicious websites to connect to an unauthenticated localhost WebSocket and perform real-time data exfiltration, remote code execution, and denial-of-service; recommended fixes are Origin header validation and use of a startup-generated session token.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.