CVE-2026-10177 | Aider-AI Aider 0.86.3 AWS EC2 Metadata Endpoint api_docs.py requests.get server-side request forgery (Issue 5075 / EUVD-2026-33497)
A vulnerability classified as critical has been found in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-10177. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is suggested to install a patch to address this issue.
The pull request to fix this issue awaits acceptance.