Impact
The vulnerability resides in Devika v1.0, where the function Coder.save_code_to_project lacks proper validation of file paths. This omission allows an attacker who can invoke the function to specify a file path that escapes the intended project directory and is written elsewhere on the filesystem. The capability to create or overwrite files beyond the designated workspace can lead to arbitrary code execution, data tampering, or privilege escalation if critical system files are modified.
Affected Systems
All installations of Devika version 1.0 are affected, as no specific subsets of functionality are limited. The product is identified only by the repository name; no vendor or additional product variants are listed in the CNA data.
Risk and Exploitability
Because the vulnerability permits write access outside a controlled directory, it has high potential impact on confidentiality, integrity, and availability of the host system. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the CVSS database. The vulnerability is not listed in the CISA KEV catalog, indicating that known exploits are not yet widely documented. The most likely attack vector is an attacker who can trigger the save function, which may be through local access or unauthenticated API endpoints if the application is exposed. Proper exploitation requires that the attacker can control the path parameter and that the affected system permits write operations outside the intended directory.
OpenCVE Enrichment