PatchSiren cyber security CVE debrief
CVE-2026-10176 Aider-AI CVE debrief
Aider-AI Aider 0.86.3 contains a SQL injection weakness in its Code Generation Workflow component. The vulnerability is remotely exploitable and has been publicly disclosed, though the vendor has not yet responded to early notification. The CVSS 4.0 vector indicates network attack vector with low privileges required and low impacts across confidentiality, integrity, and availability. The CNA-assigned weaknesses are CWE-74 (Improper Neutralization of Special Elements in Output) and CWE-89 (Improper Neutralization of Special Elements in an SQL Command).
- Vendor
- Aider-AI
- Product
- Aider
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-31
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-05-31
- Advisory updated
- 2026-07-22
Who should care
Organizations using Aider-AI Aider 0.86.3 in environments where the code generation workflow may interact with SQL databases, security teams tracking unpatched vulnerabilities with public exploits, and defenders monitoring AI-assisted development tools for injection weaknesses.
Technical summary
The vulnerability exists in an unspecified function within the Code Generation Workflow component of Aider-AI Aider version 0.86.3. Successful manipulation can result in SQL injection. The attack vector is network-based, requires low privileges, and no user interaction. The exploit has been made public. The vendor was notified via GitHub issue prior to publication but has not responded.
Defensive priority
low
Recommended defensive actions
- Review Aider-AI Aider 0.86.3 deployments and restrict network access where possible pending vendor response
- Monitor GitHub issue 5077 and the Aider-AI repository for vendor acknowledgment or patch release
- Assess whether Aider's code generation workflow interacts with any SQL databases in your environment and apply input validation or parameterized query patterns as defense in depth
- Track this CVE for status changes in NVD from 'Received' to 'Analyzed' for additional technical details
Evidence notes
The CVE record was published on 2026-05-31 with Vuldb as the CNA. The vulnerability status in NVD is 'Received'. References include the Aider-AI GitHub repository, issue #5077 (the early report to which the vendor has not responded), and multiple Vuldb pages including the CVE entry, submission record, vulnerability detail, and CTI page. The vendor field is marked low-confidence and needs review, with Vuldb identified as the reference domain candidate. No KEV entry exists. The CVSS score of 2.1 reflects limited impacts despite public exploit availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10176 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10176
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10176 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10176
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Aider-AI/aider/
-
Source reference
Unverified legacy reference
URL: https://github.com/Aider-AI/aider/issues/5077
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-10176
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/819910
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/367457
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/367457/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.