CVE-2026-7157 Details
Description
A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
A command injection vulnerability has been identified in Disler Aider-MCP-Server version 0.1.0, prior to commit b2516fa. The issue arises in the 'aider_ai_code' component, specifically within the 'src/aider_mcp_server/server.py' file. The vulnerability is triggered by manipulating the 'relative_editable_files' argument, which allows for the injection of shell metacharacters. This exploitation can be executed remotely, with published proof-of-concept available.
No official patch is available at this time. It is recommended to avoid exposing the MCP server to untrusted callers until the vulnerability is fixed. If temporary operation is necessary, place the server behind a trusted broker that validates file names against a conservative allowlist.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 27, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/disler/aider-mcp-server/ | [email protected] | ProductSource CodeVendor |
| https://github.com/disler/aider-mcp-server/issues/16 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/submit/802061 | [email protected] | Technical Description |
| https://vuldb.com/vuln/359756 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/vuln/359756/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| disler aider-mcp-server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 27, 2026 | New CVE Received | [email protected] |
Volerion