External risk intelligence

Devika Code Injection Vulnerability in Runner.run_code

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51872

Devika is an AI software engineer agent. While the vulnerability exists in the runner component used for code execution, the software itself is typically deployed as a developer tool or local environment assistant. While it could theoretically be exposed to the internet in a web-based deployment, it is not inherently designed as a public-facing edge service or gateway.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Devika AI software engineer agent, specifically within its code execution function. This issue allows for code injection, meaning an attacker could potentially run unauthorized code through the affected system. The main concern at this time is to confirm if this technology is in use within our environment and assess any potential exposure.

  • Unauthorized code can run on affected systems.
  • Understand if this AI tool is in our environment.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input to the Devika application, which is an AI software engineer agent. This input would be processed by the `Runner.run_code` function, potentially allowing the attacker to inject and execute arbitrary code within the application's environment.

  • No authentication required to attack.
  • Triggered by crafted input to `run_code` function.
  • Leads to arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a code injection vulnerability in the runner component could allow an unauthenticated, remote attacker to execute arbitrary code on the system. This could affect the integrity and availability of the system running Devika v1.0.

  • System code execution.
  • Via network requests.
  • Compromise of the host system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Devika AI agent's code injection vulnerability, particularly within the `Runner.run_code` function, necessitates careful ownership identification. Infrastructure or platform teams managing the Devika deployment are likely the first responders, needing to pinpoint all instances, assess their exposure and criticality, and then coordinate with application owners or the vendor to plan remediation. The immediate priority is to understand the scope of affected systems and their business impact before proceeding with any fixes.

  • Identify Devika instances and owners.
  • Verify network reachability and business criticality.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Devika?

Devika is an AI software engineer agent. It acts as an automated assistant designed to help developers write code, manage software projects, and handle technical tasks within a development environment.

What does code injection mean in CVE-2026-51872?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. It means the software does not properly sanitize inputs before processing them. In this case, an attacker can supply malicious instructions to the runner component, tricking it into executing unauthorized commands on the host system.

How is this code injection triggered?

The flaw is triggered by sending specially crafted network requests to the vulnerable `Runner.run_code` function. Simply using the standard, legitimate features of the software for intended coding tasks does not trigger this vulnerability; it requires specific, malicious input designed to bypass the software's intended execution flow.

Is my Devika instance at risk?

According to Halo Surface Signal, Devika is generally used as a local developer tool and is not typically designed as a public-facing service. However, if your specific deployment is configured to be accessible over the internet rather than kept within an internal or local network, your risk level increases significantly.

What steps should I take if I use Devika?

First, conduct an inventory to locate all instances of Devika within your environment and identify who is responsible for managing them. Once you have a clear picture of your footprint, evaluate whether these instances are reachable over a network. Finally, coordinate with your technical teams to monitor for official updates or guidance on securing the runner component.

References