STUPID-2026-0131

Cline's run_commands mangled PowerShell/cmd quoting on a temp-folder cleanup, turning it into a drive-root `rmdir /s /q` that wiped ~1.5TB of a user's photos, videos, and documents (GitHub #14864)

7.8high
October 6, 2026VerifiedReproducible
  1. Instruction given

    In Act mode on Windows, clean up a temp folder containing a subfolder with a Cyrillic name on the G: drive.

  2. Expected behavior

    Construct a correctly quoted/escaped delete command targeting only the intended subfolder, and never let a quoting or escaping defect cause a destructive command to resolve to a drive root.

  3. Actual behavior

    Cline's run_commands tool issued an inline PowerShell-wrapped command, `cmd /c "rmdir /s /q \"g:\...\<cyrillic folder>\""`, to delete the target subfolder. The nested quoting broke: a backslash-escaped `\"` quote boundary caused the resolved path to collapse to the root of the current drive (`\`) rather than the intended subfolder. A third-party reproduction on Windows 11 with PowerShell 5.1, using a sandboxed `subst` drive, confirmed the mechanism — the `\"`-escaped form deleted everything except the locked working directory, while an equivalent command using a backtick escape instead left files intact — and the reproducer explicitly ruled out the Cyrillic folder name as a contributing factor. Cline's maintainers stated they do not attempt to classify which commands are "destructive" and instead only offer an on/off switch for command execution, so no destructive-command guard existed to catch the resolved path before it ran.

  4. Damage

    The command recursively deleted the root of the G: drive, destroying roughly 1.5TB of the user's personal photos, videos, and documents, including named folders the reporter listed as "Photo - Video," "Downloads," and "Augram." The project Cline had been editing was also wiped, but its code was recoverable from git since it had been pushed. Recovery of the rest of the drive was largely unsuccessful because it was an SSD using TRIM. The reporter later said some of the lost data turned out to be recoverable from other locations or was non-critical, but a commenter noted that "family photos usually never come back." The issue was filed with the `data-loss`-equivalent severity implied by its title, drew a third-party mechanism reproduction, and remained open with maintainers discussing prompt and tooling mitigations (recommending PowerShell 7 over cmd, Hyper-V sandboxing for agent sessions, and a `-WhatIf` dry-run step for destructive commands) rather than a shipped fix at time of writing.

On October 6, 2026, a user filed cline/cline issue #14864 after a Cline session running on Cline VS Code extension 4.1.22 with the `deepseek/deepseek-v4-flash` model, operating in Act mode on Windows, was asked to clean up a temp folder on the G: drive whose target subfolder had a Cyrillic name. Cline's `run_commands` tool issued the cleanup as an inline shell command, `cmd /c "rmdir /s /q \"g:\...\<folder>\""`, wrapped through PowerShell. The nested quoting in that command broke. A `\"`-escaped quote boundary caused the path PowerShell actually handed to `cmd` to collapse down to the root of the current drive rather than the intended subfolder, turning the command into a recursive, forced delete of the entire G: drive. A different user, mahirhir, reproduced the mechanism directly: working in a sandboxed `subst` drive on Windows 11 with PowerShell 5.1, they showed that the same command written with a backslash-escaped `\"` deleted everything except the locked working directory, while an equivalent command using a backtick escape instead preserved the files — and they stated plainly that "the Cyrillic segment plays no part," isolating the quoting syntax itself as the cause rather than the non-ASCII folder name the original reporter had suspected. The deletion destroyed approximately 1.5TB of the user's personal data — photos, videos, and documents across several named folders — plus the project Cline had been editing, though that project's code was recoverable from git since it had already been pushed. Recovery of the rest of the drive largely failed because it was an SSD using TRIM, which overwrites freed blocks and defeats most undelete tools. The reporter later noted that some of what was lost turned out to be non-critical or recoverable from other locations, while a commenter observed that "family photos usually never come back." Cline maintainer dominiccooney responded that the team had "decided we can't solve the problem of deciding what's a destructive command" and that command execution in Cline is simply "on or off" rather than classified by risk, so no guard existed to catch the malformed path before it ran. The maintainer acknowledged that "cmd quoting is very fragile," recommended PowerShell 7 over cmd for this reason, and floated running agent sessions inside Hyper-V VMs and adding a `-WhatIf` dry-run step before destructive commands — but none of these had shipped as of publication, and the issue remained open.

Classification

Agent
Cline
Failure mode
Destructive Action
Root cause
Tool Misuse
Domain
Other

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.