kokumօtօ[verified]@__kokumotoDisclosure
CVE-2026-44211 reveals a critical WebSocket hijacking flaw in the AI agent coding tool Cline, enabling remote code execution via missing Origin header verification.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses a critical WebSocket hijack in Cline kanban (CVE‑2026‑44211) that allows RCE via missing Origin validation, providing technical details and a mitigation recommendation to avoid exposure immediately.
Apart Research[verified]@apartresearchDisclosure
Two new CVEs are announced – a Next.js SSRF affecting thousands of apps and a Cline AI agent RCE with missing origin checks – but no exploit, PoC, or patch information is given.
Maximillion (Max)[verified]@Maximillion_AIDisclosure
A new high‑severity vulnerability CVE‑2026‑44211 affecting the Cline CLI’s WebSocket server is disclosed, with detailed exploit potential but no patch or PoC available.
Gray Hats@the_yellow_fallDisclosure
The post announces CVE‑2026‑44211 against Cline AI, explaining that malicious sites can hijack terminals via WebSockets and urges users to update their CLI tools.
كاسبر سكاي@KasperskyDevDisclosure
The post discloses CVE‑2026‑44211 affecting Cline Kanban Server 2.13.0 and earlier, detailing a domain‑based hijacking that allows malicious sites to control browser dev‑tools, and notes no patch is available yet.
Cyber Threat Observatory | Alan Turing Institute@TuringCyberObsPoC
CVE-2026-44211 is a vulnerability that allows malicious sites to interfere with AI agent sessions and potentially hijack terminal input; a proof of concept has been published, but no active exploitation or patch details are reported.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-44211, a Cross‑Origin WebSocket Hijack vulnerability affecting Cline Kanban Servers 2.13.0, with a link to a detailed description on Vulmon.