PT-2026-45187 · Aider Ai · Aider

Tchen200311

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-10177

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-10177

Affected Products

Aider