SCA: security update for cline (GHSA-3cj3-hqcr-g934)

high Tenable Self-Hosted Container Security Plugin ID 448353

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline
Hub dashboard server launched by the cline dashboard command accepts WebSocket connections on the /browser
endpoint without validating the Origin header, and when ROOM_SECRET is unset for local 127.0.0.1 binds,
isAuthorizedBrowserRequest() allows attacker-controlled websites to send desktopCommand frames that read
workspace state, mutate MCP and provider settings, and trigger command execution when a provider or model
is configured. This issue is fixed in version 3.0.30. (CVE-2026-59723)

Solution

Update the cline library and its related packages to version 3.0.30 or later.

See Also

https://github.com/advisories/GHSA-3cj3-hqcr-g934

Plugin Details

Severity: High

ID: 448353

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/25/2026

Updated: 9/25/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.7

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.5

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-59723

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 7/8/2026

Reference Information

CVE: CVE-2026-59723

cwe: CWE-346