Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-91200: DevSpace 6.3.21 allows malicious container to write files on workstation
CVE-2026-91200 · published 22 days ago
Summary
The DevSpace tool (versions up to 6.3.21) can be tricked by a compromised container into creating or overwriting files on the developer's computer. This could let an attacker run unauthorized code on the workstation. Update DevSpace to a newer version or restrict containers to only trusted sources to mitigate the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| devspace | devspace | <= 6.3.21 |
Original advisory text
DevSpace through 6.3.21 Path Traversal via tar extraction
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.
References
- https://github.com/devspace-sh/devspace/issues/3290 Third Party Advisory
- https://github.com/devspace-sh/devspace Product
- https://github.com/devspace-sh/devspace/blob/7f272dcf90653fa9b42bc4347f7f3f9a52b... Third Party Advisory
- https://github.com/devspace-sh/devspace/blob/7f272dcf90653fa9b42bc4347f7f3f9a52b... Third Party Advisory
- https://www.vulncheck.com/advisories/devspace-through-6.3.21-path-traversal-via-... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91200... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91200 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.9
Critical
Type
CWE-22Path Traversal
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta