0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Cline Kanban WebSocket Flaw Enables Hijacking of AI Coding Agents (infosecurity-magazine.com)

· 81d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Unauthenticated WebSocket enables agent hijacking
  • Cline and Kanban versions prior to 1.8.2 affected
  • Patch 1.8.3 released; urgent update advised

"Oasis Security discovered a critical vulnerability in the WebSocket implementation of Cline and Kanban, two AI coding agents. Attackers can hijack agents by exploiting unauthenticated WebSocket connections, allowing code injection and sensitive data extraction. The flaw undermines trust in AI-assisted development environments and requires immediate patching. All versions prior to 1.8.3 are affected. Coordination with CERTs is underway."

Discussion Matrix

0 segments

no comments yet.