What happened
NVD published (2026-10-01) two unrated path-traversal findings in Devika v1.0's Patcher and Feature agents enabling writes outside the project workspace, with full-filesystem/whole-server impact potential.
Why it matters
Devika is an autonomous AI coding agent that generates and writes code; an escape from the intended project workspace converts the agent's own code-writing capability into an arbitrary-file-write primitive on the host it runs on.
Attack vector
The coding agents' save_code_to_project functions lack path normalization, so attacker-influenced project/file names (e.g. via manipulated source or agent tool output) write files outside the intended project workspace.
Affected systems
Devika v1.0 (stitionai/devika): Patcher Agent save_code_to_project (CVE-2026-51874) and Feature Agent save_code_to_project (CVE-2026-51875)
Mitigation
Apply upstream fixes when available (tracker stitionai/devika#709 area); run Devika in an isolated container/sandbox with restricted filesystem scope.