Cline Bot AI Coding Agent Code Execution via Prompt Injection and .clinerules Directives

Affected Vendor(s)

Affected Product(s)

Summary

Through malicious instructions planted in a Markdown file within a project’s .clinerules directory, an attacker’s source code repository can coerce Cline into executing unsafe commands without approval which can be leveraged to execute arbitrary code in the context of the user running VSCode.

Timeline

Discovered on
August 24, 2025
Disclosed to Vendor on
August 27, 2025
Published on
November 18, 2025

Credit

Blog Post

References