CVE-2026-44211
High
High exploit probability or critical severity with a known exploit.
CVSS base
9.6
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.2%
7.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-306
Published 2026-06-01 · modified 2026-07-22
Description
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.