STUPID-2026-0131
Cline's run_commands mangled PowerShell/cmd quoting on a temp-folder cleanup, turning it into a drive-root `rmdir /s /q` that wiped ~1.5TB of a user's photos, videos, and documents (GitHub #14864)
Instruction given
In Act mode on Windows, clean up a temp folder containing a subfolder with a Cyrillic name on the G: drive.
Expected behavior
Construct a correctly quoted/escaped delete command targeting only the intended subfolder, and never let a quoting or escaping defect cause a destructive command to resolve to a drive root.
Actual behavior
Cline's run_commands tool issued an inline PowerShell-wrapped command, `cmd /c "rmdir /s /q \"g:\...\<cyrillic folder>\""`, to delete the target subfolder. The nested quoting broke: a backslash-escaped `\"` quote boundary caused the resolved path to collapse to the root of the current drive (`\`) rather than the intended subfolder. A third-party reproduction on Windows 11 with PowerShell 5.1, using a sandboxed `subst` drive, confirmed the mechanism — the `\"`-escaped form deleted everything except the locked working directory, while an equivalent command using a backtick escape instead left files intact — and the reproducer explicitly ruled out the Cyrillic folder name as a contributing factor. Cline's maintainers stated they do not attempt to classify which commands are "destructive" and instead only offer an on/off switch for command execution, so no destructive-command guard existed to catch the resolved path before it ran.
Damage
The command recursively deleted the root of the G: drive, destroying roughly 1.5TB of the user's personal photos, videos, and documents, including named folders the reporter listed as "Photo - Video," "Downloads," and "Augram." The project Cline had been editing was also wiped, but its code was recoverable from git since it had been pushed. Recovery of the rest of the drive was largely unsuccessful because it was an SSD using TRIM. The reporter later said some of the lost data turned out to be recoverable from other locations or was non-critical, but a commenter noted that "family photos usually never come back." The issue was filed with the `data-loss`-equivalent severity implied by its title, drew a third-party mechanism reproduction, and remained open with maintainers discussing prompt and tooling mitigations (recommending PowerShell 7 over cmd, Hyper-V sandboxing for agent sessions, and a `-WhatIf` dry-run step for destructive commands) rather than a shipped fix at time of writing.
Classification
- Agent
- Cline
- Failure mode
- Destructive Action
- Root cause
- Tool Misuse
- Domain
- Other
- Source
- Github Issue
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.