
Affected Vendor(s)
Affected Product(s)
Summary
Through malicious instructions planted in a Markdown file within a project’s .clinerules directory, an attacker’s source code repository can coerce Cline into executing unsafe commands without approval which can be leveraged to execute arbitrary code in the context of the user running VSCode.
Timeline
Credit
Blog Post
References
Take the first step towards securing your AI. Book a demo now and we'll reach out to you.
