4.0.1785456841

    Cline (Nightly)

    Autonomous coding agent right in your IDE, capable of creating/editing files, running commands, using the browser, and more with your permission every step of the way.

    Rank#-4595
    Publisher saoudrizwanRegistry openvsx162,352Last scanned Sep 14, 2026, 03:59 PMRegistryHomepageGitHub
    Created
    2 years ago
    Last commit
    6 days ago
    Latest release
    desktop-v0.0.377 days ago

    Security Findings

    31

    Credential harvesting

    MaliciousScanner

    Hardcoded secret + sensitive file access

    pull_request_target with secrets

    MaliciousLineage

    [.github/workflows/ext-jb-test-integration.yml] pull_request_target with secrets

    Suspicious URL TLD2×

    SuspiciousScanner

    URL with suspicious TLD .xyz: https://api.ambient.xyz/v1

    URL with suspicious TLD .xyz: https://api.together.xyz/v1

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in next/dist/extension.js: Axios

    next/dist/extension.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in legacy/webview-ui/build/assets/index.js: chmod +x

    legacy/webview-ui/build/assets/index.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in next/webview-ui/build/assets/index.js: chmod +x

    next/webview-ui/build/assets/index.js

    Hardcoded secrets/API keys10×

    SuspiciousScanner

    Secret Keyword: ApiKe...****

    Secret Keyword: usern...****

    Secret Keyword: funct...****

    Private Key: BEGIN...****

    Secret Keyword: ****

    Secret Keyword: strin...****

    Secret Keyword: https...****

    Secret Keyword: API_K...****

    Secret Keyword: AWS_S...****

    Secret Keyword: My AP...****

    legacy/dist/extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: phc_k...****

    legacy/webview-ui/build/assets/index.js

    Hardcoded secrets/API keys5×

    SuspiciousScanner

    Secret Keyword: strin...****

    Private Key: BEGIN...****

    Secret Keyword: funct...****

    Secret Keyword: https...****

    Secret Keyword: phc_k...****

    next/dist/extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: phc_k...****

    next/webview-ui/build/assets/index.js

    Sensitive file access3×

    SuspiciousScanner

    Access to sensitive file: ~/.ssh

    Access to sensitive file: ~/.aws

    Access to sensitive file: homedir(),".cline","endpoints.json")}static getBundledEndpointsFilePath(){return uVr.join(t._extensionFsPath,"endpoints....

    Dangerous security bypass flags3×

    SuspiciousScanner

    Bypass flag in command: hasColor = `+i);return Error.captureStackTrace.call(a,t),a.platform=e,a.hasUnicode=r,a.hasColor=i,a.code="EMISSINGTHEME"...

    Bypass flag in content: --trust

    Bypass flag in command: `),!1,d),typeof f=="string"&&f.length>0&&t.emitter.emitReasoningDelta(f,!1,d)}return}let s=Geo(o);if(!s)return;let u=typ...

    Workflow makes outbound network call

    SuspiciousLineage

    [.github/workflows/ext-vscode-ab-package.yml] curl -sf --retry 3 -X POST "https://marketplace.visualstudio.com/_apis/public/gallery/extensionquery