CVE-2026-44211: Cline

Critical severity, CVSS 9.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

Affected products

  • Cline Cline: up to and including 2.13.0

Published 2026-06-01. Last modified 2026-07-22.