STUPID-2026-0120
Aider leaks model-provider API keys to child processes spawned via /run, /test, lint commands, and /git
Instruction given
None specific to a coding task — the exposure exists whenever Aider is running with a model-provider credential set (e.g. `OPENAI_API_KEY`) in its process environment and the user invokes `/run`, `/test`, a configured lint command, or `/git`.
Expected behavior
Commands Aider shells out to on the user's behalf — test runners, linters, and git — have no legitimate need for the model-provider credential Aider itself uses to talk to the LLM API. Aider should pass those child processes a restricted environment that excludes provider credentials, not the full process environment.
Actual behavior
In `aider/run_cmd.py`, `run_cmd_subprocess()` calls `subprocess.Popen()` without supplying a restricted `env`, so `/run`, `/test`, and configured lint commands inherit Aider's complete process environment, credentials included. Separately, Aider's `/git` handling builds `env = dict(subprocess.os.environ)` and passes that unmodified copy to the git subprocess. Both paths were traced to specific functions and cited against commit `5dc9490bb35f9729ef2c95d00a19ccd30c26339c`. The reporter demonstrated it directly: running Aider with `OPENAI_API_KEY=aider-provider-sentinel` set, then issuing `/run test -n "$OPENAI_API_KEY" && echo OPENAI_API_KEY_PRESENT` inside the session, confirms the credential is visible to the spawned process.
Damage
Filed by the reporting user (younaman) with a specific commit reference, two distinct code paths identified, and an exact reproduction command — no maintainer response recorded as of publication. No confirmed real-world exfiltration was reported. The exposure requires a test command, lint config, or git hook that an attacker controls or has compromised (e.g. via a malicious dependency or a poisoned repository) to actually read and exfiltrate the inherited variable, which narrows but does not eliminate the risk: any of those already run with the user's authority, and a leaked model-provider key adds billable API access under that identity as a distinct, separately monetizable outcome of running untrusted repository content.
Classification
- Agent
- Aider
- Failure mode
- Security Vulnerability
- Root cause
- Other
- Domain
- Security
- Source
- Github Issue
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.