CVE-2026-91200
Deferred Deferred - Pending Action

DevSpace Directory Traversal via Tar Stream

Vulnerability report for CVE-2026-91200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-23

Assigner: VulnCheck

Description

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-23
Generated
2026-10-06
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
devspace devspace to 6.3.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

DevSpace through version 6.3.21 does not properly validate tar entry names during in-pod sync operations. Attackers can exploit this by sending tar files containing parent-directory traversal sequences (like ../) to write arbitrary files on the developer's workstation, which could lead to code execution.

Detection Guidance

This vulnerability involves tar entry traversal in DevSpace's in-pod sync stream. To detect it, monitor for unexpected file writes outside intended directories during sync operations. Check DevSpace logs for tar stream errors or unusual file paths. Inspect system logs for files created with parent-directory segments (e.g., ../).

Impact Analysis

If you use DevSpace for container development, an attacker could compromise your workstation by writing malicious files outside intended directories. This could result in unauthorized code execution, data theft, or further network compromise depending on your system's access.

Compliance Impact

This vulnerability could lead to unauthorized file access or code execution, potentially violating data protection requirements under GDPR or HIPAA. Organizations may face compliance violations if sensitive data is exposed or altered due to this issue.

Mitigation Strategies

Update DevSpace to a version that properly validates tar entry names to reject parent-directory segments. Avoid using DevSpace in untrusted environments or with malicious containers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91200. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart