To make sure itâs clear in the midst of the NPM package situation: I did NOT conduct overt testing on Clineâs repository. I conducted my PoC on a mirror of Cline to confirm the prompt injection vulnerability. A different actor found my PoC on my test repository and used it to directly attack Cline and obtain the publication credentials. The same actor used the credentials to publish an unauthorize


{{#tags}}- {{label}}
{{/tags}}