Remote Code Execution Vulnerability in Aider-Chat by Aider AI
CVE-2026-85674
8.5HIGH
What is CVE-2026-85674?
Aider-Chat, developed by Aider AI, contains a vulnerability where it automatically loads a .aider.conf.yml configuration file from the repository it is executed in. This allows an attacker to specify commands that are executed without user consent during startup or on the first file edit. As a result, if a user clones a repository containing malicious configurations and runs Aider-Chat, arbitrary commands can be executed on their local machine. This flaw has been present since version 0.86.3.dev, and poses a significant risk to users who unknowingly run untrusted repositories.
Affected Version(s)
aider 0 <= 0.86.2
