CVE-2024-5752 is a critical path traversal vulnerability in stitionai/devika's project creation function, specifically in version beacf6edaa205a5a5370525407a6db45137873b3. An attacker can exploit this by crafting a project name to traverse directories, leading to arbitrary file overwrite and potential remote code execution when the application generates and saves code. This vulnerability has a CVSS score of 9.1 (Critical) due to its network-based attack vector, low complexity, and high impact on integrity and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Stitionai | Stitionai/Devika | >= unspecified, < -CNA affected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.