CVE-2026-44211

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:cline:cline:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-01 17:17

Updated : 2026-07-22 07:10


NVD link : CVE-2026-44211

Mitre link : CVE-2026-44211

CVE.ORG link : CVE-2026-44211


JSON object : View

Products Affected

cline

  • cline
CWE
CWE-306

Missing Authentication for Critical Function

CWE-1385

Missing Origin Validation in WebSockets