Path Traversal Vulnerability in DevSpace by DevSpace
CVE-2026-91200

8.7HIGH

Key Information:

Vendor

Devspace

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-91200?

DevSpace versions up to 6.3.21 are susceptible to a path traversal vulnerability due to inadequate validation of parent-directory segments in tar entry names originating from the in-pod sync stream. This flaw allows attackers leveraging a compromised container to stream specially crafted tar entries containing traversal sequences, which can lead to the unauthorized writing of arbitrary files on the developer's workstation. The potential for executing malicious code poses a significant risk to system integrity.

Affected Version(s)

devspace 0 <= 6.3.21

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.