Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

Cline Kanban WebSocket Hijack Allows Silent Data Exfiltration and Command Injection

Share the canonical public link.

Share as image

Oasis Security researchers disclosed a critical flaw in Cline's kanban server on May 7, 2026, with CVSS score of 9.7 affecting kanban npm package version 0.1.59. The local server on port 3484 exposes three unauthenticated WebSocket endpoints for runtime state, terminal I/O, and session control without origin validation. Any visited website can exfiltrate real-time workspace data and inject commands into the AI agent's terminal or kill sessions. The vulnerability was reported to Cline before publication and fixed in version 0.1.66 of the kanban package.

Below validation threshold — auto-passed without scoring

Supporting evidence