4.1.22

    Cline

    Autonomous coding agent right in your IDE, capable of creating/editing files, running commands, using the browser, and more with your permission every step of the way.

    Rank#-4366
    Publisher saoudrizwanRegistry openvsx6,811,505Last scanned Sep 30, 2026, 05:59 PMRegistryHomepageGitHub
    Created
    2 years ago
    Last commit
    6 days ago
    Latest release
    desktop-v0.0.377 days ago

    Security Findings

    20

    Credential harvesting

    MaliciousScanner

    Hardcoded secret + sensitive file access

    pull_request_target with secrets

    MaliciousLineage

    [.github/workflows/ext-jb-test-integration.yml] pull_request_target with secrets

    Suspicious URL TLD2×

    SuspiciousScanner

    URL with suspicious TLD .xyz: https://api.ambient.xyz/v1

    URL with suspicious TLD .xyz: https://api.together.xyz/v1

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in webview-ui/build/assets/index.js: chmod +x

    webview-ui/build/assets/index.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in dist/extension.js: Axios

    dist/extension.js

    Hardcoded secrets/API keys6×

    SuspiciousScanner

    Secret Keyword: https...****

    Secret Keyword: strin...****

    Private Key: BEGIN...****

    Secret Keyword: funct...****

    Secret Keyword: _STRI...****

    Secret Keyword: phc_k...****

    dist/extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: phc_k...****

    webview-ui/build/assets/index.js

    Sensitive file access3×

    SuspiciousScanner

    Access to sensitive file: ~/.ssh

    Access to sensitive file: ~/.aws

    Access to sensitive file: homedir(),".cline","endpoints.json")}static getBundledEndpointsFilePath(){return BAn.join(t._extensionFsPath,"endpoints....

    Dangerous security bypass flags2×

    SuspiciousScanner

    Bypass flag in command: `),!1,d),typeof p=="string"&&p.length>0&&t.emitter.emitReasoningDelta(p,!1,d)}return}let s=Zoo(o);if(!s)return;let u=typ...

    Bypass flag in content: --trust

    Coverage evasion (executable content over cap)

    SuspiciousScanner

    1 executable file(s) totalling 8941877 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (75.05% of code-bearing bytes reached the rules)

    Workflow makes outbound network call

    SuspiciousLineage

    [.github/workflows/ext-vscode-ab-package.yml] curl -sf --retry 3 -X POST "https://marketplace.visualstudio.com/_apis/public/gallery/extensionquery