PT-2026-56625 · Cline · Cline
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cline versions prior to 3.0.30
Description
The Cline Hub dashboard server, initiated via the
cline dashboard command, fails to validate the Origin header for WebSocket connections on the /browser endpoint. When the ROOM SECRET is unset for local 127.0.0.1 binds, the isAuthorizedBrowserRequest() function allows malicious websites to send desktopCommand frames. This can lead to the unauthorized reading of workspace state, mutation of MCP and provider settings, and trigger command execution if a provider or model is configured.Recommendations
Update to version 3.0.30.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cline