CVE-2026-57586: CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default
Summary
CodeRAG, a tool that helps AI coding agents search through code, has a security flaw in versions before 1.3.1 where it automatically runs build files from repositories without checking if they're safe. An attacker can hide malicious code in a fake Gradle repository (a build system for Java projects), and when someone uses CodeRAG to index that repository, the hidden code runs with the user's full system permissions, potentially allowing the attacker to steal data, change files, install backdoors, or crash the system.
Solution / Mitigation
Update CodeRAG to version 1.3.1 or later, which fixes this issue.
Vulnerability Details
8.6(high)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
local
low
none
required
September 15, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-57586
First tracked: September 15, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%