Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. aider-chat
  4. ›
  5. CVE-2026-10175

CVE-2026-10175: Aider is vulnerable to Code Injection via editor_coder.run function

May 31, 2026 (updated July 7, 2026)

A security flaw has been discovered in Aider-AI Aider 0.86.3.dev. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References

  • github.com/Aider-AI/aider
  • github.com/Aider-AI/aider/issues/5058
  • github.com/advisories/GHSA-7w7m-v5vp-w699
  • nvd.nist.gov/vuln/detail/CVE-2026-10175
  • vuldb.com/cve/CVE-2026-10175
  • vuldb.com/submit/819909
  • vuldb.com/vuln/367456
  • vuldb.com/vuln/367456/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-10175 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.86.2

Solution

Unfortunately, there is no solution available yet.

Impact 6.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Source file

pypi/aider-chat/CVE-2026-10175.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 00:19:38 +0000.