PT-2026-45187 · Aider · Aider

·

CVE-2026-10177

·

Published

2026-05-31

·

Updated

2026-07-13

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Aider-AI Aider version 0.86.3
Description A server-side request forgery (SSRF) issue exists in the AWS EC2 Metadata Endpoint component. This occurs within the requests.get() function located in the api docs.py file, allowing a remote attacker to manipulate requests sent by the server.
Recommendations Install the available patch for version 0.86.3. As a temporary mitigation, restrict access to the requests.get() function within the api docs.py file.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10177
GHSA-HCHG-QM84-CJ9P
PYSEC-2026-2336

Affected Products

Aider