VYPR
Critical severity9.1NVD Advisory· Published Jun 30, 2024· Updated Jun 17, 2026

CVE-2024-5926

CVE-2024-5926

Description

A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service (DoS). This issue is present in all versions of the application. The vulnerability arises due to insufficient path sanitization for the 'project-name' parameter, enabling attackers to specify paths that traverse the filesystem. By setting 'project-name' to the root directory, an attacker can cause the application to attempt to read the entire filesystem, leading to a DoS condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Stitionai/Devika2 versions
    cpe:2.3:a:stitionai:devika:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:stitionai:devika:*:*:*:*:*:*:*:*
    • (no CPE)
  • stitionai/stitionai/devikav5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.