Impact
The vulnerability exists in Devika v1.0's Patcher Agent function that persists code to a project. An attacker can craft a file path that traverses directories and writes files outside the designated project workspace, enabling placement of arbitrary files or potentially malicious scripts. This capability directly compromises the integrity and confidentiality of the file system and can lead to further exploitation such as code execution or data exfiltration. The flaw is a classic directory traversal weakness, confirmed by the presence of unvalidated path components used in file creation.
Affected Systems
Both developers and users who run Devika v1.0 on any operating system that supports the Patcher Agent are affected, as the path traversal is not limited by environment variables or other constraints. No specific vendor or product version is listed beyond Devika v1.0, so all installations of that version are potentially vulnerable.
Risk and Exploitability
Though the EPSS score is not available and the vulnerability is not present in the CISA KEV catalog, the inherent risk is high because the flaw permits arbitrary file creation. The exploitability is likely low to moderate, depending on the exposure of the Patcher Agent endpoint; if it is accessible over a network, remote attackers could create files with minimal effort. The absence of an official patch in the current data means the danger remains until a fix is released. Administrators should treat this issue as a critical file-system integrity risk.
OpenCVE Enrichment