PT-2026-29254 · Unknown · Dsai-Cline

Necboy

+1

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-30312

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DSAI-Cline (affected versions not specified)
Description The command auto-approval module in DSAI-Cline has a critical OS command injection issue that bypasses its whitelist security. The system uses string-based parsing for command validation, blocking operators like ;, &&, ||, |, and command substitution, but it does not handle newline characters within the input. An attacker can embed a newline character between a permitted command and malicious code (for example, git log malicious command). DSAI-Cline incorrectly identifies this as a safe operation and automatically approves it. The PowerShell interpreter then executes both commands sequentially, leading to Remote Code Execution without user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30312

Affected Products

Dsai-Cline