CVE-2026-10175

Source
https://cve.org/CVERecord?id=CVE-2026-10175
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10175.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10175
Aliases
Published
2026-05-31T08:45:07.461Z
Modified
2026-08-12T03:51:45.655930300Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
Details

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10175.json"
}
References

Affected packages

Git / github.com/aider-ai/aider

Affected ranges

Type
GIT
Repo
https://github.com/aider-ai/aider
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.86.3"
        },
        {
            "last_affected": "0.86.3"
        }
    ]
}

Affected versions

0.*
0.86.3
v0.*
v0.86.3.dev

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10175.json"