Sceawere

Vulnerability Detail

CVE-2026-51871UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Devika Code Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
21h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-30T21:17:12.947Z",
  "pubdate": "2026-09-30T21:17:12.947Z",
  "executiveSummary": "Devika v1.0 contains a critical Code Injection vulnerability located within the runner module. The flaw stems from the insecure handling of LLM-generated content, which is passed directly to the execution environment without adequate validation, sanitization, or sandboxing.\nThe vulnerability allows an unauthenticated attacker to achieve arbitrary code execution on the host system. By manipulating the LLM prompts or the subsequent output stream, an attacker can force the runner to execute malicious commands with the privileges of the application process.\nThis represents a high-risk security flaw as it facilitates full system compromise, unauthorized data access, and potential lateral movement within the network. Because the vulnerability exists in the core execution pipeline, successful exploitation requires no prior authentication, significantly lowering the barrier for potential adversaries.",
  "technicalDetails": "The vulnerability resides in the Runner.execute function within src/agents/runner/runner.py. The root cause is the unsafe evaluation or shell-execution of data generated by the Large Language Model (LLM) component. In the application architecture, the LLM is tasked with generating code or system commands intended for automation; however, the runner implementation fails to implement a secure abstraction layer or a restricted execution environment (sandbox) to process these instructions.\nThe attack flow initiates when the application prompts the LLM for a task. An attacker capable of influencing the input to the LLM or manipulating the context window can force the model to output arbitrary system commands, such as reverse shells, file system traversal, or credential exfiltration scripts. Because the Runner.execute function treats the output of the LLM as trusted instructions, it executes the payload directly via a system-level function, such as subprocess.run or similar execution primitives, without enforcing strict input filtering or command-line argument validation.\nThis behavior results in a classic Code Injection pattern where the input data is conflated with the execution logic of the host application. From an exploitation perspective, the attacker does not need to bypass memory protections; instead, they exploit the lack of command-side segregation. The vulnerable component is the primary automation engine, meaning that every operation executed by Devika v1.0 is susceptible to this injection if the attacker can influence the model's generation process.\nUpon successful execution, the injected payload runs with the effective UID/GID of the Devika process. If the application is deployed in a containerized environment without restrictive policies or as a root user on a host, the impact is catastrophic, leading to total system takeover. The vulnerability lacks any authentication barrier because the execution occurs as a part of the standard agent workflow, making it an inherent design flaw in how the system processes model-generated output."
}
CVE-2026-51871: Devika Code Injection Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere