{"id":"CVE-2026-85674","summary":"aider 0.86.2 Remote Code Execution via .aider.conf.yml","details":"aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user confirmation, LLM interaction, or API key. Consequently, a user who clones and runs aider inside an attacker-supplied repository achieves arbitrary command execution on their machine. The behavior is long-standing and was confirmed on 0.86.3.dev (current main).","modified":"2026-09-06T03:47:20.369826695Z","published":"2026-09-04T14:32:28.178Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85674.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85674.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85674"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/aider-0.86.2-remote-code-execution-via-aider-conf-yml"},{"type":"REPORT","url":"https://github.com/Aider-AI/aider/issues/5254"},{"type":"PACKAGE","url":"https://github.com/Aider-AI/aider"},{"type":"ARTICLE","url":"https://github.com/Aider-AI/aider/blob/v0.86.2/aider/main.py"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aider-ai/aider","events":[{"introduced":"0"},{"last_affected":"59250e070e6472967b9c83069baa33eb32d69faf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.86.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.86.2.dev","v0.86.1","v0.86.1.dev","v0.86.0","v0.85.6.dev","v0.85.5","v0.85.5.dev","v0.85.4","v0.85.4.dev","v0.85.3","v0.85.3.dev","v0.85.2","v0.85.2.dev","v0.85.1","v0.85.1.dev","v0.85.0","v0.84.1.dev","v0.84.0","v0.83.3.dev","v0.83.2","v0.83.2.dev","v0.83.1","v0.82.4.dev","v0.82.3","v0.82.3.dev","v0.82.2","v0.82.2.dev","v0.82.1","v0.82.1.dev","v0.82.0","v0.81.4.dev","v0.81.3","v0.81.3.dev","v0.81.2","v0.81.2.dev","v0.81.1","v0.81.1.dev","v0.81.0","v0.80.5.dev","v0.80.4","v0.80.4.dev","v0.80.3","v0.80.2.dev","v0.80.1","v0.80.1.dev","v0.80.0","v0.75.3.dev","v0.75.2","v0.75.2.dev","v0.75.1","v0.75.1.dev","v0.75.0","v0.74.4.dev","v0.74.3","v0.52.0","v0.51.0","v0.48.0","v0.47.1","v0.47.0","v0.46.1","v0.46.0","v0.45.1","v0.45.0","v0.44.0","v0.43.4","v0.43.3","v0.43.2","v0.43.1","v0.43.0","v0.42.0","v0.41.0","v0.40.6","v0.40.5","v0.40.4","v0.40.3","v0.40.2","v0.40.1","v0.40.0","v0.38.0","v0.37.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.29.2","v0.29.1","v0.29.0","v0.28.0","v0.27.0","v0.26.1","v0.26.0","v0.25.0","v0.24.1","v0.24.0","v0.23.0","v0.22.0","v0.21.1","v0.21.0","v0.20.0","v0.19.1","v0.19.0","v0.18.1","v0.18.0","v0.17.0","v0.16.3","v0.16.2","v0.16.1","v0.16.0","v0.15.0","v0.14.3-dev1","v0.14.2","v0.14.2-dev3","v0.14.2-dev2","v0.14.2-dev1","v0.14.1","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.1","v0.10.0","v0.9.0","v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.7.2","v0.7.0","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85674.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}