Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.
https://github.com/stitionai/devika/issues/707
https://gist.github.com/Ro1ME/946b670dfefd594a123ed4527de34088