Cline Bot AI Agent Exposed to Data Theft and Code Execution Vulnerabilities

Cline Bot AI Agent Exposed to Data Theft and Code Execution Vulnerabilities

First seen 2 Dec 2025, 18:33 UTC HackreadCyberpressCybersecuritynews 24.1

Article Content

Browse articles
ThreatCluster

Mindgard has identified four critical security vulnerabilities in the Cline Bot AI coding agent. These flaws allow for prompt injection attacks, which can lead to API key theft and remote code execution. Users of the popular VSCode extension are at risk of data leakage due to these vulnerabilities.