Cline Desktop v0.0.29 patches undici CVE-2026-1525 and enables web search by default
Cline
Following the Sep 13-14 releases covered yesterday, Cline shipped Desktop v0.0.29 (Sep 16), collapsing a vulnerable undici@5.29.0 dependency (CVE-2026-1525) and enabling web search by default in non-yolo sessions. The release train also grew the model catalog to 6,079 entries and added 3x retry with backoff on transient provider errors.
Why it matters
The undici fix closes a real vulnerability in a widely installed coding-agent CLI; the plugin layout shared across CLI, Desktop, and SDK keeps building a portable agent-plugin ecosystem.
Importance: 2/5
Security fix in a widely installed CLI
Sources
official
Releases - cline/cline