Vulnerability  ·  2026-10-03

Devika patcher/feature agents: path traversal in save_code_to_project writes files outside the workspace (CVE-2026-51874/51875)

VulnerabilityMedium impactGlobalCVE-2026-51874
NVD published CVE-2026-51874 and CVE-2026-51875 on 2026-10-01 (unrated): path traversal in Devika v1.0's save_code_to_project lets agents write files outside the intended workspace — attackable via a malicious repo/prompt steering the coding agent.
AI coding agents write files as a core capability; an unconfined write path turns a malicious repo into a host file-write primitive on the machine running the coding agent.
Attacker-controlled path values in the save_code_to_project functions of the Patcher and Feature agents escape the project workspace directory, enabling arbitrary file writes on the server.
Devika v1.0
Apply upstream fix (path confinement in save_code_to_project) or avoid running Devika in untrusted-project scenarios.
NVD CVE-2026-51874NVD CVE-2026-51875Ro1ME gist — Devika Patcher path traversal
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →