Cline Bot AI Coding Agent Code Execution via Prompt Injection and .clinerules Directives

Affected Vendor(s)

Affected Product(s)

Summary

Through malicious instructions planted in a Markdown file within a project’s .clinerules directory, an attacker’s source code repository can coerce Cline into executing unsafe commands without approval which can be leveraged to execute arbitrary code in the context of the user running VSCode.

Timeline

24th August, 2025 Identified flaws
27th August 2025 Reported to vendor
31st October 2025 Product re-tested
18th November 2025 Findings published

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.