External risk intelligence

Devika Feature Agent Path Traversal

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51875

Devika is an AI software engineering agent designed for local development and coding tasks. It is intended to run in a developer's private environment or workspace rather than as a public-facing internet service or edge gateway. Consequently, it is normally isolated from the public internet.

Path Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A path traversal vulnerability has been identified in a specific AI software engineering agent, allowing unauthorized file writes outside of its intended scope. This could lead to broader system compromise if the affected agent is running in an environment where such access is possible. The primary concern is confirming whether this agent is deployed in a manner that exposes it to this risk.

  • Agents can be tricked into writing files anywhere.
  • Matters if the agent runs outside isolated developer environments.
  • Confirm deployment and exposure risks.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the Devika application. This request would target the `save_code_to_project` function within the Feature Agent. If successful, the attacker could write files to any location on the server, leading to a compromise of the entire system.

  • No authentication required.
  • Path traversal in file saving function.
  • Full server compromise.

Live Threat

Current exploitation, exposure, and threat context

The `save_code_to_project` function in Devika could allow an attacker to write files outside of the designated project area. This occurs when the application is accessible over a network and does not require authentication.

  • Server files and code integrity.
  • Path traversal to write files elsewhere.
  • Potential compromise of the entire server.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Devika's `save_code_to_project` function could allow attackers to write files outside the project directory, potentially impacting the entire server. The first practical step is to identify all Devika deployments, determine their reachability and criticality, and then assign ownership for remediation planning.

  • Application or platform owners should own the issue.
  • Verify Devika's reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Devika?

Devika is an AI software engineering agent designed to assist with coding tasks and development workflows. It functions as an automated tool that developers use to write, organize, and manage code within their local project environments.

What does CVE-2026-51875 mean?

This CVE describes a path traversal vulnerability, classified as CWE-22. It occurs when software fails to properly sanitize user input when handling file paths. In this specific case, the `save_code_to_project` function allows an attacker to manipulate file paths to write data outside of the intended project directory and onto other parts of the host server.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request to the Devika application that specifically targets the `save_code_to_project` function. The vulnerability does not require any authentication to exploit. It is only triggered if the application processes malicious input designed to navigate outside the authorized workspace.

Why should I care about this Devika vulnerability?

You should care if your Devika instance is reachable over a network. According to Halo Surface Signal, Devika is generally designed for private, isolated development environments rather than public-facing services. If your deployment is exposed to the public internet, it significantly increases the likelihood that an attacker could reach the vulnerable function.

Do I need to take action if I use Devika?

Yes. Start by identifying where Devika is running in your environment and confirm its network reachability. Once you have an inventory of your deployments, assess the risk based on whether the agent is accessible to unauthorized users. Assign ownership to the relevant team to monitor for updates or configuration changes that can secure the file-saving process.

References