
Cline collapses the last lingering undici.29.0 copy onto 7.x to close CVE-2026-1525, a residual of an earlier fix. The root override pins undici to ">=7.29.0 <8", killing the nested dependency from dify-ai-provider. If your lockfile still dragged 5.x around, it's gone now. The desktop sidecar gets a deterministic fix for the doubled text and missing rows in the live stream. The observer stream now gates on ClineCore's subscription, replacing the timer-based dedupe. Boot-id handling stays. OpenHands switches issue readiness type detection from label to body. The bug/enhancement criteria stay unchanged, tests pass: 89. langchain-openai hits 1.6.1, adding Azure AD auth support with OpenAI 3.8. Also a bump to max_completion_tokens in the cache breakpoint integration test. Cline's webview learns to flag attached images a selected model can't use and offers a model switch. undici 5.x's reign in Cline might be over. #AIAgents https://repojournal.com/showcase/ai-agents/2026-09-09/cline-collapses-lingering-undici-5-x-to-fix-cve-2026-1525
Post summary
The article describes a dependency override that resolves CVE-2026-1525 in the Cline project, effectively patching the vulnerability without mentioning active exploitation or a proof of concept.




