Executive brief
Cline Hub is a local dashboard for the Cline AI code assistant that developers launch on their machine. The dashboard's WebSocket endpoint fails to validate the origin of incoming connections, allowing any website visited by the developer to inject malicious MCP (Model Context Protocol) servers with arbitrary shell commands. Since dashboard sessions auto-approve all tool use by default, this leads to command execution under the developer's account when the injected server is activated.
Technical details
The vulnerability is a cross-origin WebSocket hijacking (CSWSH) in the Cline Hub dashboard's `/browser` endpoint. Root cause: (1) when ROOM_SECRET environment variable is unset (the default for localhost binds), the isAuthorizedBrowserRequest() function returns true unconditionally, bypassing all authorization; (2) the WebSocket upgrade handler never validates the HTTP Origin header. Attack vector: network-adjacent (requires the victim to visit an attacker-controlled website while the dashboard runs on localhost). Preconditions: default configuration (ROOM_SECRET unset, binding to 127.0.0.1), browser with same-origin WebSocket access. Attacker can: read workspace/session state via desktopCommand frames, inject arbitrary MCP server entries (including stdio commands) into cline_mcp_settings.json, control active Cline sessions with auto-approve enabled to execute commands, and exfiltrate credentials. A patch was merged on 2026-06-23 (PR #11724) that validates both Host and Origin headers against the configured dashboard origin/host.
Affected products
- Cline Cline <= 3.0.24
Timeline
- 2026-06-23: disclosed: Advisory published
- 2026-06-23: patched: Fix merged in PR #11724 (commit d092709)