Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.8 Node.js & npm GHSA-3cj3-hqcr-g934 CVE-2026-59723

Cline Hub Dashboard: Cross-Origin WebSocket Hijacking Allows Local Code Execution (CVE-2026-59723)

The Cline Hub dashboard server, started via the `cline dashboard` CLI command, accepts WebSocket connections on its `/browser` endpoint without validating the Origin header. In the default local configuration this lets any website a developer visits hijack the dashboard session, modify settings, and potentially execute commands on the developer's machine.

Synthesized by AI from 1 source · updated 1 hour ago

AI summary

A vulnerability has been disclosed in `@cline/cline-hub`, the dashboard server component of the Cline project, launched through the `cline dashboard` CLI command. The issue, tracked as CVE-2026-59723 (GHSA-3cj3-hqcr-g934), is a Cross-Origin WebSocket Hijacking (CWE-346) flaw in the `/browser` endpoint. It affects the default local configuration of the dashboard and can allow a malicious web page to interact with an active Cline dashboard session without any authentication. A fixed version, 3.0.30, is available.

What happened

A security advisory describes a Cross-Origin WebSocket Hijacking vulnerability in the Cline Hub dashboard server's `/browser` WebSocket endpoint. When the dashboard is started with its default local configuration (bound to 127.0.0.1) and no `ROOM_SECRET` environment variable is set, the server's authorization check unconditionally allows connections, and the server does not validate the HTTP Origin header on WebSocket upgrade requests. As a result, JavaScript running on any website a developer happens to visit can open a WebSocket connection to the local dashboard and send commands to it.

Technical cause

According to the advisory, the dashboard's `normalizeRoomSecret()` function converts an unset or empty `ROOM_SECRET` environment variable to `undefined`, and the local default host (127.0.0.1) is permitted to start without a secret. The function `isAuthorizedBrowserRequest()` then returns `true` unconditionally whenever `roomSecret` is `undefined`, and no Origin header check is performed anywhere in the WebSocket upgrade path for the `/browser` endpoint. Browsers include the Origin header on WebSocket connections but leave enforcement to the server; since the server does not inspect it, any cross-origin page can connect. Additionally, dashboard sessions are created with a default tool policy of `autoApprove: true` for all tools, and an `upsert_mcp_server` command handler writes attacker-supplied MCP server configuration entries (including arbitrary `stdio` command/argument pairs) directly to the Cline settings file without further authorization checks.

Why it matters

Because the dashboard binds to a local port and skips Origin validation by default, an attacker does not need network access to the victim's machine — a single visit to a malicious or compromised web page while the dashboard is running is enough to trigger the issue. The advisory describes a confirmed proof of concept in which a cross-origin page injects a malicious `stdio` MCP server entry into the victim's Cline settings file, which executes a shell command the next time Cline activates that MCP server. Because dashboard-created sessions auto-approve all tools by default, an attacker who can reach an active session with a configured AI provider could also potentially direct the agent to perform file operations, run commands, or access credentials available in the developer's environment, without any confirmation prompt being shown.

Who is affected

Developers who run the `cline dashboard` command from the `cline` npm package in its default local configuration (host 127.0.0.1, no `ROOM_SECRET` set) are affected. The advisory's proof of concept was demonstrated against `cline` version 3.0.24. The affected range covers versions of `cline` starting from version 0 up to, but not including, the fixed version 3.0.30.

Affected versions

Versions of `cline` from 0 up to (but not including) 3.0.30 are affected, per the advisory's affected-range data.

Fixes and mitigation

The advisory lists 3.0.30 as the fixed version of `cline`. Organizations and developers running the Cline Hub dashboard should upgrade to this fixed version. No further mitigation steps beyond upgrading are described in the available facts.

Recommended action

Developers using `cline dashboard` should upgrade `cline` to version 3.0.30 as soon as practical. Until upgraded, avoid running the dashboard while browsing untrusted websites, since any open browser tab could interact with an active dashboard session on the default local configuration.

PatchBriefing score

4.8 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

This issue carries a CVSS base score of 8.8 (AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), reflecting high impact to confidentiality, integrity, and availability once a developer visits a malicious page while the dashboard is running, albeit requiring an adjacent attack vector and user interaction. The computed PatchBriefing score of 4.8 out of a possible higher scale reflects that, despite the high CVSS base score, there is no known exploitation in the wild, no public exploit code referenced in the available facts, and the vulnerability does not meet the thresholds for unauthenticated remote exploitation without user interaction in this scoring model. A fix is available, which also factors into the overall assessment.

Affected versions

cline < 3.0.30
vulnerable
≥ 3.0.30
patched

Reported fixes

The advisory lists 3.0.30 as the fixed version of `cline`. Organizations and developers running the Cline Hub dashboard should upgrade to this fixed version. No further mitigation steps beyond upgrading are described in the available facts.

How this was built

1 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
Unified report
Cline Hub Dashboard: Cross-Origin WebSocket Hijacking Allows Local Code Execution (CVE-2026-59723)
1 article · 1 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email