Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85674— aider 0.86.2 Remote Code Execution via .aider.conf.yml

Quick assessment

Affected
Aider-AI aider
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

aider(即 aider-chat)会自动从其启动所在的 git 仓库根目录加载名为 的配置文件。一个精心构造的仓库可以设置 (在启动时执行)或 (在首次编辑文件时执行)。aider 通过 shell 执行这些命令(使用 且 ),过程中不需要用户确认、LLM 交互或 API 密钥。因此,当用户在攻击者提供的仓库中克隆并运行 aider 时,便会在其机器上实现任意命令执行。这一行为由来已久,并在最新版本 0.86.3.dev(当前 main 分支)中得到了确认。

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1059.001 · PowerShell

Affected Version Matrix 1

VendorProduct Version RangeStatus
Aider-AI aider ≤ 0.86.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85674

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
aider 0.86.2 Remote Code Execution via .aider.conf.yml
Source: CVE Program / CVE List V5
Vulnerability Description
aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user confirmation, LLM interaction, or API key. Consequently, a user who clones and runs aider inside an attacker-supplied repository achieves arbitrary command execution on their machine. The behavior is long-standing and was confirmed on 0.86.3.dev (current main).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Aider-AI aider 0 ~ 0.86.2 -

II. Public POCs for CVE-2026-85674

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85674

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85674 (1)

Proof of Concept for CVE-2026-85674 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85674

No comments yet


Leave a comment