Description
In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary file write via path traversal
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in Devika v1.0's Patcher Agent function that persists code to a project. An attacker can craft a file path that traverses directories and writes files outside the designated project workspace, enabling placement of arbitrary files or potentially malicious scripts. This capability directly compromises the integrity and confidentiality of the file system and can lead to further exploitation such as code execution or data exfiltration. The flaw is a classic directory traversal weakness, confirmed by the presence of unvalidated path components used in file creation.

Affected Systems

Both developers and users who run Devika v1.0 on any operating system that supports the Patcher Agent are affected, as the path traversal is not limited by environment variables or other constraints. No specific vendor or product version is listed beyond Devika v1.0, so all installations of that version are potentially vulnerable.

Risk and Exploitability

Though the EPSS score is not available and the vulnerability is not present in the CISA KEV catalog, the inherent risk is high because the flaw permits arbitrary file creation. The exploitability is likely low to moderate, depending on the exposure of the Patcher Agent endpoint; if it is accessible over a network, remote attackers could create files with minimal effort. The absence of an official patch in the current data means the danger remains until a fix is released. Administrators should treat this issue as a critical file-system integrity risk.

Generated by OpenCVE AI on October 1, 2026 at 22:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a patched version of Devika once available
  • Implement server-side checks to reject file paths containing '..' or absolute references before calling save_code_to_project
  • Restrict write permissions of the service process so that even if a file is created, it cannot execute or modify sensitive system files

Generated by OpenCVE AI on October 1, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in Devika V1.0 Patcher Agent Allows Arbitrary File Write
First Time appeared Stitionai
Stitionai devika
Weaknesses CWE-22
Vendors & Products Stitionai
Stitionai devika

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.
References

Subscriptions

Stitionai Devika
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-01T21:29:27.275Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:02.147

Modified: 2026-10-01T22:17:02.147

Link: CVE-2026-51874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')