PT-2026-56625 · Cline · Cline

·

CVE-2026-59723

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cline versions prior to 3.0.30
Description The Cline Hub dashboard server, initiated via the cline dashboard command, fails to validate the Origin header for WebSocket connections on the /browser endpoint. When the ROOM SECRET is unset for local 127.0.0.1 binds, the isAuthorizedBrowserRequest() function allows malicious websites to send desktopCommand frames. This can lead to the unauthorized reading of workspace state, mutation of MCP and provider settings, and trigger command execution if a provider or model is configured.
Recommendations Update to version 3.0.30.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59723
GHSA-3CJ3-HQCR-G934

Affected Products

Cline