CVE-2026-51874: Path Traversal
Published Oct 1, 2026
·Updated
In Devika v1.0, the Patcher Agent savecodetoproject function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.
Affected Software
1 affected component
Devika Devika=1.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is in the Patcher Agent's save_code_to_project function. An attacker would need a way to cause that function to process a path they control or influence.
2
What is the potential impact of successful exploitation?
Successful exploitation can write files outside the intended project workspace. The provided information does not specify which external paths are writable or what permissions the affected process has.