Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5c57-rqjx-35g2 | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability |
Wed, 03 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:cline:cline:*:*:*:*:*:*:*:* |
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cline
Cline cline |
|
| Vendors & Products |
Cline
Cline cline |
Mon, 01 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches. | |
| Title | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability | |
| Weaknesses | CWE-1385 CWE-306 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-04T03:55:45.848Z
Reserved: 2026-05-05T15:13:47.571Z
Link: CVE-2026-44211
Updated: 2026-06-01T17:44:58.723Z
Status : Analyzed
Published: 2026-06-01T17:17:07.617
Modified: 2026-06-03T19:52:24.553
Link: CVE-2026-44211
No data.
OpenCVE Enrichment
Updated: 2026-06-01T19:45:20Z
Github GHSA