CVE-2026-44211Disclosure(cline / cline)

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cline cline systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-1385

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cline

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 12 signals
  • Disclosure: 9 classified signals
  • Peaked 6d ago at 3 mentions (2026-05-12); latest day: 1
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
cline

Deep dive

Activity timeline12 mentions / 9d
01223Mentions · 2026-05-09: 1Mentions · 2026-05-11: 2Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-17: 1Mentions · 2026-06-01: 1Mentions · 2026-06-02: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-06-02: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-08: 105-0905-1105-1205-1305-1405-1706-0106-0206-08
Signal classification3 categories
Disclosure
975.0%
Patch
216.7%
PoC
18.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-091
Disclosure1
2026-05-112
Disclosure2
2026-05-123
Disclosure3
2026-05-131
Patch1
2026-05-141
Patch1
2026-05-171
Disclosure1
2026-06-011
Disclosure1
2026-06-021
PoC1
2026-06-081
Disclosure1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Critical Alert: CVE-2026-44211 in Cline AI allows malicious sites to hijack your terminal and steal data via WebSockets. Update your CLI tools now. #ClineAI #AISecurity #CyberSecurity #InfoSec #RCE #DevSecOps #VulnerabilityAlert #CVE #WebSecurity https://securityonline.info/cline-ai-agent-vulnerability-cve-2026-44211-websocket-hijacking/ https://t.co/UUg5JEUbC4

    Post summary

    The post announces CVE‑2026‑44211 against Cline AI, explaining that malicious sites can hijack terminals via WebSockets and urges users to update their CLI tools.

    04090590
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    AIエージェントコーディングツールClineに重大(Critical)な脆弱性。CVE-2026-44211はCVSSスコア9.6で、任意の訪問先サイトがAIエージェントの制御を奪取し遠隔コード実行が可能なもの。kanban npmパッケージのWebSocketサーバにOriginヘッダ検証が無いのが悪い。 https://securityonline.info/cline-ai-agent-vulnerability-cve-2026-44211-websocket-hijacking/

    Post summary

    CVE-2026-44211 reveals a critical WebSocket hijacking flaw in the AI agent coding tool Cline, enabling remote code execution via missing Origin header verification.

    050601.1K
    7.6K followersView on X
  • كاسبر سكاي@KasperskyDev
    Disclosure

    ثغرة اختطاف اتصال عبر النطاقات في وكيل البرمجة كلاين تتيح للمواقع الخبيثة التحكم بأدوات المطوّر داخل المتصفح. المنتج : Cline Kanban Server المعرّف : CVE-2026-44211 الإصدارات المتأثرة : Cline 2.13.0 and prior الحل : No patch available yet #CVE #DevSecOps #AI

    Post summary

    The post discloses CVE‑2026‑44211 affecting Cline Kanban Server 2.13.0 and earlier, detailing a domain‑based hijacking that allows malicious sites to control browser dev‑tools, and notes no patch is available yet.

    11001264
    40.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Cline kanban WebSocket hijack → RCE (CVE-2026-44211) The kanban server lacks Origin validation, allowing any website to connect, leak workspace data, and inject commands into running AI agent sessions. 👉 Affects kanban ≤0.1.59 (via Cline ≤2.13.0) - avoid exposure immediately

    Post summary

    The post discloses a critical WebSocket hijack in Cline kanban (CVE‑2026‑44211) that allows RCE via missing Origin validation, providing technical details and a mitigation recommendation to avoid exposure immediately.

    00030160
    237 followersView on X
  • Apart Research@apartresearch
    Disclosure

    Two CVEs this week, same missing spec. CVE-2026-44578: Next.js SSRF, tens of thousands of apps exposed. CVE-2026-44211: Cline AI agent RCE, no Origin check on local WebSocket. Spec the boundary or someone will. SPS Hackathon, May 22-24 https://linktr.ee/apartresearch https://t.co/cVkn0BzTih

    Post summary

    Two new CVEs are announced – a Next.js SSRF affecting thousands of apps and a Cline AI agent RCE with missing origin checks – but no exploit, PoC, or patch information is given.

    00010268
    1.4K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    PoC

    CVE-2026-44211 (Cline Kanban). A malicious site can interfere with AI agent sessions, and potentially hijack terminal input. PoC exists See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-01/TIER_2_CVE-2026-44211.md #CyberSecurity #DPI #AIsecurity #DeveloperSecurity #WebSockets

    Post summary

    CVE-2026-44211 is a vulnerability that allows malicious sites to interfere with AI agent sessions and potentially hijack terminal input; a proof of concept has been published, but no active exploitation or patch details are reported.

    0000056
    48 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44211 Cross-Origin WebSocket Hijack Vulnerability in Cline Kanban Servers 2.13.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44211

    Post summary

    The text announces CVE-2026-44211, a Cross‑Origin WebSocket Hijack vulnerability affecting Cline Kanban Servers 2.13.0, with a link to a detailed description on Vulmon.

    0000049
    4.0K followersView on X
  • ttfr ai トレンド@neural_nw_ai
    Patch

    【緊急】ClineユーザーはすぐにアップデートをCVSS 9.7(CVE-2026-44211)。ローカルWebSocket Origin未検証でRCE可能。v2.13.0未満の全バージョンが対象。AIコーディングツールのセキュリティ審査の甘さが再び問われている。 https://cybersecuritynews.com/cline-ai-agent-vulnerability/ #Cline #CVE #セキュリティ

    Post summary

    CVE‑2026‑44211 is a critical RCE vulnerability in Cline AI agents (CVSS 9.7) affecting all pre‑v2.13.0 versions; users are urged to apply the available patch immediately.

    0000068
    10 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Critical CVSS 9.6 vulnerability discovered in the Cline Kanban server. Info, incl. fix info, at vulnerability alert service, SecAlerts: CVE-2026-44211: https://secalerts.co/vulnerability/CVE-2026-44211 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202644211 #Cline #Kanban https://t.co/RAS1E1cfEx

    Post summary

    A newly disclosed CVE‑2026‑44211 against Cline Kanban, rated CVSS 9.6, with fix information available on SecAlerts.

    00000103
    809 followersView on X
  • Maximillion (Max)@Maximillion_AI
    Disclosure

    Any website you have open right now can read your Cline agent sessions. CVE-2026-44211 dropped this morning. CVSS 9.3. No patch. The Cline CLI bundles a WebSocket server on localhost:3484 with zero origin validation. A malicious page silently connects and gets: → Your workspace file paths → Git branch names → Live AI agent chat → The ability to inject prompts into a running session WebSockets bypass CORS entirely. The browser just... sends them. No fix available yet. Check how many tabs you have open. https://cybersecuritynews.com/cline-ai-agent-vulnerability/ #DevTools #AITools #CyberSecurity

    Post summary

    A new high‑severity vulnerability CVE‑2026‑44211 affecting the Cline CLI’s WebSocket server is disclosed, with detailed exploit potential but no patch or PoC available.

    0000058
    10 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical Vulnerability in Cline Kanban Server — CVE-2026-44211 🔍 Unauthorized Access / Sensitive Data Exposure Attackers could access sensitive info & control running tasks ⚠️ https://vulert.com/vuln-db/CVE-2026-44211 #CyberSecurity #DevSecOps #CVE2026 #OpenSourceSecurity https://t.co/ZOHbsqkEO2

    Post summary

    The tweet announces a new critical vulnerability (CVE‑2026‑44211) in Cline Kanban Server, outlining unauthorized access and data exposure risks but providing no PoC, exploit, or mitigation details.

    0000031
    126 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical Vulnerability in Cline Kanban Server — CVE-2026-44211 🔍 Unauthorized Access / Sensitive Data Exposure Attackers could access sensitive info & control running tasks ⚠️ 🔗 https://vulert.com/vuln-db/CVE-2026-44211 #CyberSecurity #DevSecOps #CVE2026 #OpenSourceSecurity https://t.co/xT16hwKeUy

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-44211) in the Cline Kanban Server that allows unauthorized access and sensitive data exposure, with no proof of exploitation or patch discussion provided.

    0000032
    126 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appclinecline---

Explore more