{"id":"CVE-2026-10177","aliases":["GHSA-hchg-qm84-cj9p"],"title":"Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint","summary":"Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","vendor":"aider-chat","product":"aider-chat","ecosystem":"pip","affected":["aider-chat <= 0.86.2"],"published":"2026-05-31","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hchg-qm84-cj9p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10177"},{"url":"https://github.com/Aider-AI/aider/issues/5075"},{"url":"https://github.com/Aider-AI/aider/pull/5137"},{"url":"https://github.com/Aider-AI/aider"},{"url":"https://vuldb.com/cve/CVE-2026-10177"},{"url":"https://vuldb.com/submit/819911"},{"url":"https://vuldb.com/vuln/367458"},{"url":"https://vuldb.com/vuln/367458/cti"}],"tags":["osv","pip"],"epss":0.00209,"epssPercentile":0.11412,"ingestedAt":"2026-07-08T18:25:50.047Z","slug":"CVE-2026-10177","body":"## Overview\n\nA security vulnerability has been detected in Aider-AI Aider 0.86.3.dev. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance.\n\n## Affected packages\n\n- `aider-chat <= 0.86.2`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}