@ai-sdk/harness-cline is vulnerable to Path Traversal
77
High Risk
The Cline harness file tools (read, write, edit, grep, glob, ls) accept absolute paths and traversal sequences that escape the session working directory, and they follow symlinks that point outside the allowed roots. A model steered through prompt injection can use a file tool with a malicious path to read files belonging to concurrent sessions, including environment variables, credentials, and configuration, and in allow-edits mode can write or change files outside the workspace. The fix normalizes requested paths, uses their real paths, and rejects paths outside the session working directory or explicitly configured readable roots, and recursive searches no longer follow symlinks.
You are affected if you are using a version that falls within the vulnerable range and you use the Cline harness file tools in a sandbox shared with other sessions or credentials.
@ai-sdk/harness-cline is vulnerable to Path Traversal in versions 1.0.0 - 1.0.7.
Upgrade the @ai-sdk/harness-cline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.