CVE-2026-91200
moderatePath Traversal in DevSpace In-Pod Sync Enables Arbitrary File Write and RCE
DevSpace through 6.3.21 fails to reject parent-directory (../) segments in tar entry names arriving over its in-pod file-sync stream, a CWE-22 path traversal flaw. When a developer uses DevSpace's sync or hot-reload against a container an attacker controls — for example a malicious or compromised third-party image — the attacker can craft tar entries that escape the intended sync directory and write arbitrary files on the developer's workstation. Because files can be placed anywhere on the local machine, this enables code execution with the developer's privileges. Anyone running DevSpace 6.3.21 or earlier who syncs with containers they do not fully control is affected. No public PoC is known, the issue is not on CISA's KEV list, and there is no evidence of exploitation in the wild.
What to do: Upgrade to a DevSpace release newer than 6.3.21 as soon as a fixed version is available. Until then, avoid using the in-pod sync/hot-reload feature with any image you did not build or fully trust, and consider running DevSpace inside an isolated VM or container to limit the blast radius of a traversal write. Review your workstation for unexpected files created outside sync directories if you have synced with third-party images recently.
| Loft Labs DevSpace | through 6.3.21 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.