CVE-2026-51873

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.

Published 2026-10-01. Last modified 2026-10-06.