External risk intelligence

Devika Runner Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51871

Devika is an AI software engineering agent. While these tools are typically used by developers locally or within internal environments for code generation and task automation, they are sometimes exposed as web-based interfaces or API services for team collaboration, making internet reachability possible depending on the specific deployment configuration.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Devika, an AI software engineering agent, related to code injection. This issue arises from the direct execution of AI-generated content, potentially allowing unauthorized code to run on affected systems. The primary concern is to understand if and how this technology is deployed within our environment to assess the relevance of this vulnerability.

  • AI code execution vulnerability found.
  • Understand AI agent use for risk assessment.
  • Confirm AI tool deployment and impact.

Attack Path

How an attacker could exploit the issue

An attacker could achieve arbitrary code execution by exploiting a vulnerability in Devika's Runner.execute function. This function directly executes content generated by a large language model, meaning an attacker could craft malicious input that, once processed, allows them to run their own code on the affected system. This could lead to a complete compromise of the system.

  • No authentication required to reach the vulnerable component.
  • Input to the Runner.execute function triggers the vulnerability.
  • Risk of arbitrary code execution and system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Devika's `Runner.execute` function could allow for arbitrary code execution when the system processes LLM-generated content. The system's ability to directly execute this content means that malicious instructions embedded within it could be run without proper sanitization, impacting the integrity and availability of the affected system.

  • Arbitrary code execution.
  • Direct execution of LLM-generated content.
  • System compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Devika's execution of LLM-generated content requires immediate attention from the teams responsible for AI development tools and application security. The first practical step is to identify all instances of Devika, determine their exposure and criticality, and locate the accountable owners to plan remediation.

  • Identify AI development tool owners.
  • Confirm Devika instances and exposure.
  • Plan targeted code injection mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Devika?

Devika is an AI software engineering agent designed to assist with coding tasks and automated workflows. Developers use it to generate code and manage complex projects by leveraging large language models to interact with files and execute commands. Because it is built to perform work autonomously, it contains specific components responsible for running the code it produces.

What does CWE-94 mean for CVE-2026-51871?

CWE-94 is the weakness class for Code Injection. In the context of this CVE, it means the application is tricked into executing code that it was not intended to run. Specifically, the software's Runner component fails to properly inspect instructions provided by the AI, allowing that external or generated input to be interpreted as valid system commands and executed automatically.

How is this code injection vulnerability triggered?

The vulnerability is triggered when the system's Runner component processes content generated by an LLM without sufficient security checks. If an attacker can influence the AI's output, they can inject malicious instructions that the Runner will then execute. Simply having the service running is not enough; the specific path of executing unverified generated content must be invoked to trigger the flaw.

Is my Devika instance at risk?

According to Halo Surface Signal, risk depends on your deployment. While Devika is often used locally, it can be configured as a web-based interface or API service for team collaboration. If your instance is internet-facing or accessible outside of a restricted internal environment, it is more reachable by unauthorized parties, increasing the likelihood that this vulnerability could be misused.

How should I respond to this vulnerability?

Start by identifying every instance of Devika currently running in your environment and determining who is responsible for each deployment. Once identified, evaluate how these tools are exposed to the network and prioritize restricting access to any instances that do not require external availability. Coordinate with the relevant engineering teams to review how these agents handle generated code until a formal fix is implemented.

References