people · May 21, 2026
Cline Kanban WebSocket Hijack Allows Silent Data Exfiltration and Command Injection
Share the canonical public link.
Oasis Security researchers disclosed a critical flaw in Cline's kanban server on May 7, 2026, with CVSS score of 9.7 affecting kanban npm package version 0.1.59. The local server on port 3484 exposes three unauthenticated WebSocket endpoints for runtime state, terminal I/O, and session control without origin validation. Any visited website can exfiltrate real-time workspace data and inject commands into the AI agent's terminal or kill sessions. The vulnerability was reported to Cline before publication and fixed in version 0.1.66 of the kanban package.