Description
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.
Problem types
CWE-306: Missing Authentication for Critical Function
CWE-1385: Missing Origin Validation in WebSockets
Product status
References
github.com/.../cline/security/advisories/GHSA-5c57-rqjx-35g2
github.com/.../cline/security/advisories/GHSA-5c57-rqjx-35g2