GHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
Summary
The Cline Hub dashboard server accepts WebSocket connections on the `/browser` endpoint without checking the `Origin` header (the source of the connecting website), allowing any website a developer visits to hijack the connection and send commands. When `ROOM_SECRET` is not set (the default for local connections), this vulnerability is especially dangerous because attackers can inject malicious MCP servers (tools that extend Cline's capabilities) into the victim's settings file and execute arbitrary commands, since dashboard sessions automatically approve all tool actions by default.
Vulnerability Details
EPSS: 0.2%
Yes
September 24, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-3cj3-hqcr-g934
First tracked: September 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 92%