OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51873

HIGH · CVSS 8.8 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Devika v1.0 is susceptible to a Directory Traversal vulnerability in the Coder.save_code_to_project function, enabling attackers to write files outside the designated project workspace. This could lead to unauthorized file access or manipulation, potentially compromising the integrity of the system. Organizations using this version of Devika should prioritize remediation to mitigate risks associated with this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51873
Severity
HIGH
CVSS
8.8
EPSS
0.26%

Original NVD Description

Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.