Cline Bot AI Coding Agent Code Execution via Prompt Injection and TOCTOU Script Invocation

Affected Vendor(s)

Affected Product(s)

Summary

Cline is vulnerable to prompt injection when analyzing source code files. This prompt injection can be used to execute arbitrary code by breaking the model’s ability to analyze an entire potential execution chain for safety.

Timeline

Discovered on
August 24, 2025
Disclosed to Vendor on
August 27, 2025
Published on
November 18, 2025

Credit

Blog Post

References