CVE-2026-51875: Path Traversal
Published Oct 1, 2026
·Updated
In Devika v1.0, the Feature Agent savecodetoproject function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compromising the entire server.
Affected Software
1 affected component
Devika Devika=v1.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
Which code path should be prioritized for review?
Prioritize the Feature Agent's save_code_to_project function. The issue is a path traversal flaw in that function that can write files outside the intended project workspace.
2
Are versions other than v1.0 identified as affected?
The available information specifically identifies Devika v1.0. It does not provide affected or unaffected version ranges beyond that version.