Command Injection Affecting agent-coderag package, versions [,1.3.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Command Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-AGENTCODERAG-17675203
  • published29 Jun 2026
  • disclosed19 Jun 2026
  • creditUnknown

Introduced: 19 Jun 2026

CVE NOT AVAILABLE CWE-78  (opens in a new tab)

How to fix?

Upgrade agent-coderag to version 1.3.1 or higher.

Overview

agent-coderag is a Lightweight semantic code search and distillation utility for AI coding agents. It solves the API knowledge gap via real-time local signature extraction and intent analysis without PyTorch. Optimized for token efficiency, it compresses codebase context into compact semantic summaries stored in a local DuckDB vector similarity index.

Affected versions of this package are vulnerable to Command Injection in the sync process. An attacker can execute arbitrary code with the victim's operating system privileges by inducing the victim to run the tool against a directory containing a malicious gradlew script. This is possible because the process unconditionally executes a repository-controlled script without validating its content or integrity, allowing compromise of confidentiality, integrity, and availability.

References

CVSS Base Scores

version 4.0
version 3.1