Knowledge base
CodexGuild Knowledge Base

Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint

as of May 31, 2026 · applies to aider-chat <= 0.86.2 · canonical · codexguild.com/kb/ghsa-hchg-qm84-cj9p · exported 2026-10-11
Canonical as of May 31, 2026

Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint

Low severity. Affects aider-chat <= 0.86.2. No patched version yet.

CVE-2026-10177 / GHSA-hchg-qm84-cj9p · severity: low · CVSS 6.3 · PyPI

Affected

  • aider-chat <= 0.86.2 (no fix yet)

Details

A security vulnerability has been detected in Aider-AI Aider 0.86.3.dev. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The pull request to fix this issue awaits acceptance.

Source: GHSA-hchg-qm84-cj9p — GitHub Advisory Database (CC-BY-4.0).