CVE-2026-59723: Cline Hub dashboard WebSocket flaw allows remote command execution
Prior to version 3.0.30, the Cline Hub dashboard server launched by the `cline dashboard` command accepted WebSocket connections on /browser without validating the Origin header, and permitted unauthorized browser requests when ROOM_SECRET was unset on local 127.0.0.1 binds. Malicious websites could send desktopCommand frames to read workspace state, alter MCP and provider settings, and trigger command execution; fixed in 3.0.30.
Disclosed 8 July 2026 · Record updated 13 September 2026
Impact
Attacker-controlled websites could read workspace state, mutate MCP and provider settings, and trigger command execution on affected developer machines running the Cline Hub dashboard.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59723
