0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Critical WebSocket Hijacking Vulnerability in Cline AI Coding Agent (oasis.security)

· 68d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Cline Kanban server runs unauthenticated local WebSocket
  • Allows cross-origin websocket hijacking from any site
  • Leads to remote code execution via the AI agent

"A critical 9.7-severity vulnerability in Cline's Kanban server allowed unauthenticated local WebSockets to be hijacked by malicious websites, enabling remote code execution on AI coding agents. The flaw underscores risks in local development tools using WebSocket without origin verification."

Discussion Matrix

0 segments

no comments yet.