Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.
The attack involves hijacking a WebSocket connection from the Cline Kanban server through unauthorized requests from another source (cross-origin). The vulnerability is related to CWE-306 (missing authentication for critical function) and CWE-1385 (improper WebSocket origin verification), meaning the server does not properly verify whether the request comes from a trusted source. As a result, a malicious website visited by the victim can establish an unauthorized WebSocket connection to the local Cline server and perform actions on behalf of the user.
An attacker can gain unauthorized access to the victim's WebSocket session, potentially leading to complete compromise of confidentiality, integrity, and availability of data and functions in the Cline environment — including the ability to execute coding agent commands.
At the time of publication, there are no publicly available patches. Monitor the vendor's repository (https://github.com/cline/cline) and apply patches immediately upon release. Until a fix is available, it is recommended to restrict access to the Cline Kanban servers component and avoid using Cline in environments where the user may visit untrusted websites.
Cline in versions 2.13.0 and earlier (as SDK, IDE extension, or CLI assistant) using the Cline Kanban servers component
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCline
APPCline≤ 2.13.0