CVE-2026-51871

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.

https://gist.github.com/Ro1ME/3067a5bd69dcd35ffc98dc41ca611242
https://github.com/stitionai/devika/issues/714