Intel

AIKIDO-2026-891128

@ai-sdk/harness-cline is vulnerable to Path Traversal

Path TraversalGHSA-222v-gj5h-ff73 Published 5 days ago

77

High Risk

This Affects:

JS@ai-sdk/harness-cline
1.0.0 - 1.0.7
Fixed in 1.0.8
Are you affected? Scan for Free

TL;DR

The Cline harness file tools (read, write, edit, grep, glob, ls) accept absolute paths and traversal sequences that escape the session working directory, and they follow symlinks that point outside the allowed roots. A model steered through prompt injection can use a file tool with a malicious path to read files belonging to concurrent sessions, including environment variables, credentials, and configuration, and in allow-edits mode can write or change files outside the workspace. The fix normalizes requested paths, uses their real paths, and rejects paths outside the session working directory or explicitly configured readable roots, and recursive searches no longer follow symlinks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the Cline harness file tools in a sandbox shared with other sessions or credentials.

Background info

@ai-sdk/harness-cline is vulnerable to Path Traversal in versions 1.0.0 - 1.0.7.

How to fix this

Upgrade the @ai-sdk/harness-cline library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform