Vulnerability  ·  2026-10-03

Devika AI coding agent: path traversal in Patcher/Feature agent save_code_to_project lets agents write outside the project workspace

VulnerabilityMedium impactGlobalCVE-2026-51874
NVD published (2026-10-01) two unrated path-traversal findings in Devika v1.0's Patcher and Feature agents enabling writes outside the project workspace, with full-filesystem/whole-server impact potential.
Devika is an autonomous AI coding agent that generates and writes code; an escape from the intended project workspace converts the agent's own code-writing capability into an arbitrary-file-write primitive on the host it runs on.
The coding agents' save_code_to_project functions lack path normalization, so attacker-influenced project/file names (e.g. via manipulated source or agent tool output) write files outside the intended project workspace.
Devika v1.0 (stitionai/devika): Patcher Agent save_code_to_project (CVE-2026-51874) and Feature Agent save_code_to_project (CVE-2026-51875)
Apply upstream fixes when available (tracker stitionai/devika#709 area); run Devika in an isolated container/sandbox with restricted filesystem scope.
NVD CVE-2026-51874NVD CVE-2026-51875
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →