Junglewise Threat Intelligence

CVE-2026-7316: eiliyaabedini aider-mcp command injection in code_with_ai tool

CVE-2026-7316 · Severity: high · CVSS 7.3 · Published 2026-04-28

Executive brief

Aider-mcp is a tool that allows AI agents to interact with local codebases. A security flaw allows a remote attacker to execute arbitrary commands on the host system by providing specially crafted file names or directory paths. This could lead to a total compromise of the server, including unauthorized data access, file modification, or service disruption.

Technical details

A command injection vulnerability exists in the 'code_with_ai' tool of aider-mcp due to unsafe shell command construction in 'aider_ai_code.py'. The application uses 'subprocess.check_output' with 'shell=True' to execute 'git diff' commands, interpolating user-provided 'working_dir' and 'editable_files' arguments without proper sanitization or escaping. A remote attacker can inject shell metacharacters (e.g., semicolons or backticks) into these arguments to execute arbitrary OS commands. The vulnerability is present up to commit 667b914; as of the advisory date, no official patch has been confirmed by the vendor.

Affected products

  • eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af

Timeline

  • 2026-04-10: other: Vulnerability discovered by researcher Winegee
  • 2026-04-12: disclosed: Public issue report opened on GitHub repository
  • 2026-04-28: advisory: NVD/VulDB advisory published

References