{"id":"PYSEC-2026-2336","summary":"Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint","details":"A security vulnerability has been detected in Aider-AI Aider 0.86.3.dev. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance.","aliases":["CVE-2026-10177","GHSA-hchg-qm84-cj9p"],"modified":"2026-07-13T16:31:27.900042682Z","published":"2026-07-13T15:35:22.603521Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10177"},{"type":"WEB","url":"https://github.com/Aider-AI/aider/issues/5075"},{"type":"WEB","url":"https://github.com/Aider-AI/aider/pull/5137"},{"type":"PACKAGE","url":"https://github.com/Aider-AI/aider"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-10177"},{"type":"WEB","url":"https://vuldb.com/submit/819911"},{"type":"WEB","url":"https://vuldb.com/vuln/367458"},{"type":"WEB","url":"https://vuldb.com/vuln/367458/cti"},{"type":"PACKAGE","url":"https://pypi.org/project/aider-chat"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hchg-qm84-cj9p"}],"affected":[{"package":{"name":"aider-chat","ecosystem":"PyPI","purl":"pkg:pypi/aider-chat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.86.2"}]}],"versions":["0.10.0","0.10.1","0.11.0","0.11.1","0.12.0","0.13.0","0.14.0","0.14.1","0.14.2","0.15.0","0.16.0","0.16.1","0.16.2","0.16.3","0.17.0","0.18.0","0.18.1","0.19.0","0.19.1","0.20.0","0.21.0","0.21.1","0.22.0","0.23.0","0.24.0","0.24.1","0.25.0","0.26.0","0.26.1","0.27.0","0.28.0","0.29.0","0.29.1","0.29.2","0.30.0","0.30.1","0.31.0","0.31.1","0.32.0","0.33.0","0.34.0","0.35.0","0.36.0","0.37.0","0.38.0","0.39.0","0.40.0","0.40.1","0.40.5","0.40.6","0.41.0","0.42.0","0.43.0","0.43.2","0.43.3","0.43.4","0.44.0","0.45.0","0.45.1","0.46.0","0.46.1","0.47.0","0.47.1","0.48.0","0.48.1","0.49.0","0.49.1","0.5.0","0.50.0","0.50.1","0.51.0","0.51.1","0.52.0","0.52.1","0.53.0","0.54.0","0.54.10","0.54.11","0.54.12","0.54.2","0.54.3","0.54.4","0.54.5","0.54.6","0.54.7","0.54.8","0.54.9","0.55.0","0.56.0","0.57.0","0.57.1","0.58.0","0.58.1","0.59.0","0.59.1","0.6.1","0.6.2","0.6.4","0.6.6","0.60.0","0.60.1","0.61.0","0.62.0","0.62.1","0.63.0","0.63.1","0.63.2","0.64.0","0.64.1","0.65.0","0.65.1","0.66.0","0.67.0","0.68.0","0.69.0","0.69.1","0.7.0","0.7.1","0.7.2","0.70.0","0.71.0","0.71.1","0.72.0","0.72.1","0.72.2","0.72.3","0.73.0","0.74.0","0.74.1","0.74.2","0.74.3","0.75.0","0.75.1","0.75.2","0.76.0","0.76.1","0.76.2","0.77.0","0.77.1","0.78.0","0.79.0","0.79.1","0.79.2","0.8.0","0.8.1","0.8.2","0.8.3","0.80.0","0.80.1","0.80.2","0.80.3","0.80.4","0.81.0","0.81.1","0.81.2","0.81.3","0.82.0","0.82.1","0.82.2","0.82.3","0.83.0","0.83.1","0.83.2","0.84.0","0.85.0","0.85.1","0.85.2","0.85.3","0.85.4","0.85.5","0.86.0","0.86.1","0.86.2","0.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/aider-chat/PYSEC-2026-2336.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}