๐Ÿ” CVE Alert

CVE-2026-7157

HIGH 7.3

disler aider-mcp-server aider_ai_code server.py command injection

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-77 CWE-74
Vendor disler
Product aider-mcp-server
Published Apr 27, 2026
Stay Ahead of the Next One

Get instant alerts for disler aider-mcp-server

Be the first to know when new high vulnerabilities affecting disler aider-mcp-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

disler / aider-mcp-server
b2516fa466d0d851932da92ee6d0e66946db9efc

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/359756 vuldb.com: https://vuldb.com/vuln/359756/cti vuldb.com: https://vuldb.com/submit/802061 github.com: https://github.com/disler/aider-mcp-server/issues/16 github.com: https://github.com/disler/aider-mcp-server/

Credits

๐Ÿ” SmallW (VulDB User) VulDB CNA Team