Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution. | |
| Title | DevSpace through 6.3.21 Path Traversal via tar extraction | |
| First Time appeared |
Devspace
Devspace devspace |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:devspace:devspace:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devspace
Devspace devspace |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T22:10:57.135Z
Reserved: 2026-09-14T21:55:43.719Z
Link: CVE-2026-91200
No data.
Status : Received
Published: 2026-09-14T23:19:00.630
Modified: 2026-09-14T23:19:00.630
Link: CVE-2026-91200
No data.
OpenCVE Enrichment
No data.