Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
- Severity:
- High
Description
The kanban npm package (used by the cline CLI) starts a WebSocket server on 127.0.0.1:3484 with no Origin header validation. Any website a developer visits can silently connect to the kanban server via WebSocket and:
1.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.13.0
References
Related Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Storybook Dev Server is Vulnerable to WebSocket Hijacking - CVE-2026-27148
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- Waku: Cross-Origin CSRF on RSC Server Action Dispatch - CVE-2026-49455
You might also like:
- Tags:
- npm
- cline
Anything's wrong? Let us know Last updated on June 09, 2026


