Stitionai
Stitionai Devika: vulnerabilidades y CVE
Stitionai Devika tiene 14 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses2
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51872 | Sin puntuar | 0.21% | — | 30 sept 2026 | Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py. |
| CVE-2026-51871 | Crítica (9.8) | 0.23% | — | 30 sept 2026 | Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated… |
| CVE-2024-5752 | Crítica (9.1) | 1.6% | — | 20 mar 2025 | A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a5a5370525407a6db45137873b3, the project name is not validated,… |
| CVE-2024-7790 | Media (5.4) | 0.34% | — | 14 ago 2024 | A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded user input. |
| CVE-2024-6331 | Media (6.5) | 0.50% | — | 4 ago 2024 | stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with… |
| CVE-2024-40422 | Crítica (9.1) | 11% | — | 24 jul 2024 | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and… |
| CVE-2024-5549 | Alta (8.1) | 0.29% | — | 9 jul 2024 | A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability… |
| CVE-2024-5711 | Media (6.1) | 0.48% | — | 8 jul 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into the chat input. This vulnerability is due to the lack of input… |
| CVE-2024-5926 | Crítica (9.1) | 0.86% | — | 30 jun 2024 | A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service (DoS). This issue is present in all… |
| CVE-2024-5712 | Alta (8.1) | 0.26% | — | 28 jun 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a… |
| CVE-2024-5820 | Alta (8.8) | 0.79% | — | 27 jun 2024 | An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all… |
| CVE-2024-5548 | Alta (7.5) | 1.0% | — | 27 jun 2024 | A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can exploit this vulnerability by manipulating the 'project_name'… |
| CVE-2024-5547 | Alta (7.5) | 1.0% | — | 27 jun 2024 | A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of the… |
| CVE-2024-5334 | Alta (7.5) | 2.1% | — | 27 jun 2024 | A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot'… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.