Medium severity6.3NVD Advisory· Published May 31, 2026· Updated Jul 22, 2026
CVE-2026-10177
CVE-2026-10177
Description
A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aider-chatPyPI | <= 0.86.2 | — |
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-hchg-qm84-cj9pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-10177ghsaADVISORY
- github.com/Aider-AI/aider/issues/5075nvdWEB
- github.com/Aider-AI/aider/pull/5137nvdWEB
- vuldb.com/cve/CVE-2026-10177nvdWEB
- vuldb.com/submit/819911nvdWEB
- vuldb.com/vuln/367458nvdWEB
- vuldb.com/vuln/367458/ctinvdWEB
News mentions
0No linked articles in our index yet.