CRITICAL🇵🇱 Wersja polska

CVE-2026-44211

CVSS 9.6v3.1pub. 2026-06-01upd. 2026-07-22

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

🤖 AI Analysis
How it works

The attack involves hijacking a WebSocket connection from the Cline Kanban server through unauthorized requests from another source (cross-origin). The vulnerability is related to CWE-306 (missing authentication for critical function) and CWE-1385 (improper WebSocket origin verification), meaning the server does not properly verify whether the request comes from a trusted source. As a result, a malicious website visited by the victim can establish an unauthorized WebSocket connection to the local Cline server and perform actions on behalf of the user.

Impact

An attacker can gain unauthorized access to the victim's WebSocket session, potentially leading to complete compromise of confidentiality, integrity, and availability of data and functions in the Cline environment — including the ability to execute coding agent commands.

Mitigation & patch

At the time of publication, there are no publicly available patches. Monitor the vendor's repository (https://github.com/cline/cline) and apply patches immediately upon release. Until a fix is available, it is recommended to restrict access to the Cline Kanban servers component and avoid using Cline in environments where the user may visit untrusted websites.

Who is affected

Cline in versions 2.13.0 and earlier (as SDK, IDE extension, or CLI assistant) using the Cline Kanban servers component

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Cline

    APP
    Cline
    ≤ 2.13.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-30313CRITICAL9.8PL ✓same product

Command Injection w module auto-akceptacji komend DSAI-Cline (RCE)

CVE-2026-59723HIGH8.8PL ✓same product

Cline: brak walidacji nagłówka Origin w endpoincie WebSocket /browser