PT-2026-45184 · Aider Ai · Aider

Tchen200311

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-10175

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-10175

Affected Products

Aider