← back

CVE-2026-91200

HIGH · 8.8
hype MOSTLY HYPE · 28 hack

Fresh NVD listing amplified; no PoC, no KEV, no urgent patching signal yet.

What: DevSpace versions up to 6.3.21 allow path traversal in tar extraction from in-pod sync streams, enabling arbitrary file write and code execution on developer workstations (CVSS 8.8).

Why it matters: Published yesterday; high CVSS score reflects code execution risk. No KEV listing yet, no public PoC confirmed in chatter, no vendor advisory visible in posts. Social signal is pure NVD/metadata amplification with no defender triage or exploitation reports.

Where it's seen: Three near-identical posts on Bluesky quoting NVD description verbatim; references to aggregator sites. No security researcher PoC, no vendor patch announcement, no defender discussion of active exploitation.

RISK: HIGH — High CVSS, code execution, but newly disclosed with no patch or mitigation visible.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 12:53:08 PM

Description

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses