What happened
NVD published CVE-2026-51874 and CVE-2026-51875 on 2026-10-01 (unrated): path traversal in Devika v1.0's save_code_to_project lets agents write files outside the intended workspace — attackable via a malicious repo/prompt steering the coding agent.
Why it matters
AI coding agents write files as a core capability; an unconfined write path turns a malicious repo into a host file-write primitive on the machine running the coding agent.
Attack vector
Attacker-controlled path values in the save_code_to_project functions of the Patcher and Feature agents escape the project workspace directory, enabling arbitrary file writes on the server.
Affected systems
Devika v1.0
Mitigation
Apply upstream fix (path confinement in save_code_to_project) or avoid running Devika in untrusted-project scenarios.