Remote Code Execution Vulnerability in CodeRAG by Naranor
CVE-2026-57586
8.6HIGH
What is CVE-2026-57586?
CodeRAG, developed by Naranor, is a utility designed for semantic code search aimed at AI coding agents. A vulnerability existed in versions prior to 1.3.1 where the default synchronization flow for indexed paths could be exploited. Specifically, the process did not adequately validate the content or integrity of executables, which allowed an attacker to craft a malicious Gradle repository. If indexed by a victim, this could lead to the execution of arbitrary code with the victim’s OS privileges, risking potential data disclosure, modification, persistence, or denial of service in the user environment. The vulnerability was addressed in version 1.3.1.
Affected Version(s)
agent-coderag < 1.3.1
