logo

Cline Kanban Flaw Lets Websites Hijack AI Coding Agents

ID: 93aea572-d2da-55cc-af25-9ddc94d942a0

STIX ID: report--93aea572-d2da-55cc-af25-9ddc94d942a0

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

...
...

A critical vulnerability (CVSS 9.7) in Cline's Kanban local server (Kanban npm v0.1.59) exposes three unauthenticated WebSocket endpoints that lack origin validation, allowing any webpage a developer visits to silently exfiltrate workspace data, push commands into the agent's terminal (leading to remote code execution), or kill agent sessions; Oasis Security disclosed the issue and a patch is available in v0.1.66, with the recommendation to disable Cline's default "bypass permissions" to limit impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.