Description
Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Directory traversal enabling writes to arbitrary files outside the intended project workspace
Action: Patch or Mitigate
AI Analysis

Impact

The vulnerability resides in Devika v1.0, where the function Coder.save_code_to_project lacks proper validation of file paths. This omission allows an attacker who can invoke the function to specify a file path that escapes the intended project directory and is written elsewhere on the filesystem. The capability to create or overwrite files beyond the designated workspace can lead to arbitrary code execution, data tampering, or privilege escalation if critical system files are modified.

Affected Systems

All installations of Devika version 1.0 are affected, as no specific subsets of functionality are limited. The product is identified only by the repository name; no vendor or additional product variants are listed in the CNA data.

Risk and Exploitability

Because the vulnerability permits write access outside a controlled directory, it has high potential impact on confidentiality, integrity, and availability of the host system. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the CVSS database. The vulnerability is not listed in the CISA KEV catalog, indicating that known exploits are not yet widely documented. The most likely attack vector is an attacker who can trigger the save function, which may be through local access or unauthenticated API endpoints if the application is exposed. Proper exploitation requires that the attacker can control the path parameter and that the affected system permits write operations outside the intended directory.

Generated by OpenCVE AI on October 1, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire and install a version of Devika that removes the directory traversal flaw or applies an official patch if available
  • Modify the Coder.save_code_to_project routine to sanitise all file path inputs, rejecting paths that contain '..' or absolute references
  • Configure strict filesystem permissions so that the process running Devika cannot write outside the designated workspace directory

Generated by OpenCVE AI on October 1, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Directory Traversal in Devika's Code Save Function Allows Write Outside Project Workspace
Weaknesses CWE-22

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-01T21:28:38.277Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:02.017

Modified: 2026-10-01T22:17:02.017

Link: CVE-2026-51873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')