Executive brief
Aider, an AI-powered pair programming tool, is vulnerable to a security flaw where its built-in web scraping feature can be tricked into making requests to internal network addresses. If the tool is running in a cloud environment like AWS, an attacker could potentially use this to access sensitive internal metadata or security credentials. This could lead to unauthorized access to cloud resources or the exposure of private configuration data.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Aider's built-in URL scraping path (specifically within aider/scrape.py). The application fails to implement guardrails against private IP addresses, loopback interfaces, or cloud metadata endpoints (such as 169.254.169.254). An attacker can provide a malicious URL in a repository file or prompt, causing Aider to fetch sensitive data like AWS EC2 IAM security credentials. The vulnerability is triggered when Aider attempts to scrape documentation or context from provided URLs. A pull request (#5137) has been submitted to implement hostname validation, redirect revalidation, and IP-level blocking to mitigate this issue.
Affected products
- Aider-AI aider-chat <= 0.86.2
Timeline
- 2026-04-26: disclosed: Issue first reported on GitHub
- 2026-05-16: other: Pull request with fix submitted
- 2026-05-31: advisory: GitHub Advisory and CVE published