Impact
DevSpace fails to reject parent-directory segments in the names of files inside tar archives that are streamed from containers. When these archives are extracted onto the developer workstation, the path traversal is not blocked, allowing an attacker to write arbitrary files outside the expected sync directory. By placing executables or scripts in these locations the attacker can run code on the workstation, which is effectively a remote code execution scenario. This flaw corresponds to CWE-22, the classic path‑traversal weakness.
Affected Systems
All releases of DevSpace up to and including version 6.3.21 are affected. The issue arises in the in‑pod sync component that extracts tar streams. The affected product is DevSpace (namespace devspace:devspace).
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity flaw. The EPSS score of < 1% indicates a low exploitation probability, which is compounded by the fact that the vulnerability is not listed in the CISA KEV catalog. Nevertheless the flaw remains a serious risk in environments where developers allow arbitrary container streams. Attackers must control a container that can stream a crafted tar archive; once they do, they can overwrite files on the host and achieve code execution. Given the severity and the nature of the flaw, the risk to systems that expose sync streams to untrusted containers is high.
OpenCVE Enrichment