Impact
The Vulnerability: The code that handles saving user generated code in Devika v1.0 allows a malicious actor to inject file paths that escape the intended project directory. This oversight enables arbitrary write operations beyond the workspace boundaries. The consequence is that an attacker could create critical files, overwrite system configuration, or otherwise compromise the full server. The weakness is a typical Path Traversal flaw, classified as CWE-22.
Affected Systems
This flaw exists in Devika version 1.0. Users who run that version with the default Feature Agent interface are exposed. The description does not name additional variants or higher releases, so only the stated version is known to be affected.
Risk and Exploitability
Because the function is publicly exposed through the Feature Agent, the attack vector is likely remote, via legitimate user interfaces or API calls. No exploit score or CVSS rating is provided, and the EPSS is missing, making the precise risk hard to quantify. However, an exploit would let the attacker write any file the process can reach, potentially allowing full control of the host. The vulnerability is not listed in CISA KEV, suggesting no confirmed public exploits yet, but the severity of an arbitrary file write is high and warrants immediate attention.
OpenCVE Enrichment