Path Traversal Vulnerability in DevSpace by DevSpace
CVE-2026-91200
8.7HIGH
What is CVE-2026-91200?
DevSpace versions up to 6.3.21 are susceptible to a path traversal vulnerability due to inadequate validation of parent-directory segments in tar entry names originating from the in-pod sync stream. This flaw allows attackers leveraging a compromised container to stream specially crafted tar entries containing traversal sequences, which can lead to the unauthorized writing of arbitrary files on the developer's workstation. The potential for executing malicious code poses a significant risk to system integrity.
Affected Version(s)
devspace 0 <= 6.3.21
