Description
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution. | |
| Title | DevSpace through 6.3.21 Path Traversal via tar extraction | |
| First Time appeared |
Devspace
Devspace devspace |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:devspace:devspace:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devspace
Devspace devspace |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T22:10:57.135Z
Reserved: 2026-09-14T21:55:43.719Z
Link: CVE-2026-91200
No data.
Status : Received
Published: 2026-09-14T23:19:00.630
Modified: 2026-09-14T23:19:00.630
Link: CVE-2026-91200
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')