Executive brief
Cline's local Kanban server exposes three unauthenticated WebSocket endpoints that accept connections from any website without validating the origin. An attacker can exploit this from any web page a developer visits to leak sensitive project data (file paths, task descriptions, git branches, AI chat messages), hijack running AI agent sessions to inject arbitrary commands (leading to remote code execution), or terminate active tasks.
Technical details
The vulnerability is a missing Origin header validation on three WebSocket endpoints in the kanban npm package: /api/runtime/ws (runtime state stream), /api/terminal/io (terminal input/output), and /api/terminal/control (task termination). Lacking both Origin validation and authentication, the server accepts and services connections from malicious cross-origin pages. Attack vector is network-based and requires user interaction (victim must visit an attacker-controlled webpage while Kanban is running). Upon connection, the runtime WebSocket immediately broadcasts workspace filesystem paths, task metadata, git information, and AI chat messages. The terminal I/O endpoint writes attacker-controlled bytes directly to the agent's pseudo-terminal, allowing arbitrary command injection with agent privileges. The terminal control endpoint accepts stop messages that terminate running tasks. A proof-of-concept demonstrates full exploitation including data exfiltration and remote code execution via terminal hijacking. No patches are currently available; recommended fixes include validating the Origin header, implementing session tokens, and requiring authentication on terminal endpoints.
Affected products
- Cline kanban 0.1.59 and earlier
Timeline
- 2026-05-08: disclosed
- 2026-05-08: advisory