📦 Devika

by Stitionai

🔍 What is Devika?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40422

CRITICAL CVSS 9.1 Jul 24, 2024

This vulnerability allows attackers to perform path traversal attacks via the snapshot_path parameter in Devika v1's API endpoint. By manipulating this parameter, attackers can access sensitive files ...

CVE-2024-6331

HIGH CVSS 7.5 Aug 4, 2024

This vulnerability allows attackers to read sensitive local files through prompt injection in the Devika AI assistant. It affects systems running Devika with Google Gemini 1.0 Pro integration where sa...

CVE-2024-5549

HIGH CVSS 8.1 Jul 9, 2024

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information like logs, browser sessions, and settings containing private API keys. This vulnerability als...

CVE-2024-5712

HIGH CVSS 8.1 Jun 28, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in the stitionai/devika application allows attackers to trick authenticated users into performing unauthorized actions like deleting projects or chang...

CVE-2024-5820

HIGH CVSS 8.8 Jun 27, 2024

An unprotected WebSocket connection in stitionai/devika allows malicious websites to connect to the backend and issue commands as the authenticated user. This enables unauthorized command execution an...

CVE-2024-5547

HIGH CVSS 7.5 Jun 27, 2024

A directory traversal vulnerability in the stitionai/devika repository allows attackers to download arbitrary PDF files from the system by manipulating the 'project_name' parameter in API requests. Th...

CVE-2024-7790

MEDIUM CVSS 6.5 Aug 14, 2024

A stored cross-site scripting (XSS) vulnerability exists in DevikaAI software where improperly decoded user input allows attackers to inject malicious scripts. These scripts execute in victims' browse...

CVE-2024-5711

MEDIUM CVSS 6.1 Jul 8, 2024

A stored Cross-Site Scripting (XSS) vulnerability in the stitionai/devika chat feature allows attackers to inject malicious JavaScript payloads that execute in users' browsers. This affects all versio...