PatchSiren

Aider-AI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Aider-AI CVE published 2026-05-31

CVE-2026-10174

Aider-AI Aider 0.86.3 contains a protection mechanism failure in its Pre-commit Hook Handler, specifically within aider/args.py. The git-commit-verify argument can be manipulated to bypass intended protections. The vulnerability is remotely exploitable and has publicly available exploit material. The vendor was notified via an issue report prior to publication but had not responded at the time of CVE publ [truncated]