GHSA-7w7m-v5vp-w699

Suggest an improvement
Source
https://github.com/advisories/GHSA-7w7m-v5vp-w699
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7w7m-v5vp-w699/GHSA-7w7m-v5vp-w699.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7w7m-v5vp-w699
Aliases
Published
2026-05-31T09:31:00Z
Modified
2026-07-13T16:43:33Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Aider is vulnerable to Code Injection via editor_coder.run function
Details

A security flaw has been discovered in Aider-AI Aider 0.86.3.dev. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids":  [
        "CWE-74"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-07T19:36:46Z",
    "nvd_published_at":  "2026-05-31T09:16:15Z",
    "severity":  "LOW"
}
References

Affected packages

PyPI / aider-chat

Package

Name
aider-chat
View open source insights on deps.dev
Purl
pkg:pypi/aider-chat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.86.2

Affected versions

0.*
0.5.0
0.6.1
0.6.2
0.6.4
0.6.6
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.9.0
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.13.0
0.14.0
0.14.1
0.14.2
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.21.0
0.21.1
0.22.0
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.29.1
0.29.2
0.30.0
0.30.1
0.31.0
0.31.1
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.38.0
0.39.0
0.40.0
0.40.1
0.40.5
0.40.6
0.41.0
0.42.0
0.43.0
0.43.2
0.43.3
0.43.4
0.44.0
0.45.0
0.45.1
0.46.0
0.46.1
0.47.0
0.47.1
0.48.0
0.48.1
0.49.0
0.49.1
0.50.0
0.50.1
0.51.0
0.51.1
0.52.0
0.52.1
0.53.0
0.54.0
0.54.2
0.54.3
0.54.4
0.54.5
0.54.6
0.54.7
0.54.8
0.54.9
0.54.10
0.54.11
0.54.12
0.55.0
0.56.0
0.57.0
0.57.1
0.58.0
0.58.1
0.59.0
0.59.1
0.60.0
0.60.1
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.63.2
0.64.0
0.64.1
0.65.0
0.65.1
0.66.0
0.67.0
0.68.0
0.69.0
0.69.1
0.70.0
0.71.0
0.71.1
0.72.0
0.72.1
0.72.2
0.72.3
0.73.0
0.74.0
0.74.1
0.74.2
0.74.3
0.75.0
0.75.1
0.75.2
0.76.0
0.76.1
0.76.2
0.77.0
0.77.1
0.78.0
0.79.0
0.79.1
0.79.2
0.80.0
0.80.1
0.80.2
0.80.3
0.80.4
0.81.0
0.81.1
0.81.2
0.81.3
0.82.0
0.82.1
0.82.2
0.82.3
0.83.0
0.83.1
0.83.2
0.84.0
0.85.0
0.85.1
0.85.2
0.85.3
0.85.4
0.85.5
0.86.0
0.86.1
0.86.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-7w7m-v5vp-w699/GHSA-7w7m-v5vp-w699.json"