Aider Coding Assistant Configuration Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

Mindgard found that Aider can automatically execute commands from a malicious repository-level configuration file when a project is opened, creating a zero-click execution path.

Timeline

Discovered on
December 17, 2025
Disclosed to Vendor on
December 17, 2025
Published on
May 12, 2026

Credit

Blog Post

References