CVE-2024-5752
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 352
Summary
CVE-2024-5752 is a newly identified path traversal vulnerability affecting the stitionai/devika project, specifically its project creation functionality. In the impacted version beacf6edaa205a5a5370525407a6db45137873b3, an attacker can exploit this flaw by providing a crafted project name during creation. Unvalidated input allows directory traversal, potentially leading to arbitrary file overwrite. This can result in the application generating and saving malicious code to the specified project directory, posing a risk for remote code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.