{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/devspace--6.3.21/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:loft:devspace:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-91200"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DevSpace (\u003c= 6.3.21)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","path-traversal","devspace"],"_cs_type":"advisory","_cs_vendors":["DevSpace"],"content_html":"\u003cp\u003eDevSpace versions 6.3.21 and earlier contain a security vulnerability, identified as CVE-2026-91200, related to how the application handles tar entries during the in-pod sync process. The software fails to properly sanitize or reject entries containing parent-directory segments (e.g., ../) within the tar stream received from a container. An attacker capable of operating a malicious or compromised container can exploit this oversight to perform directory traversal when syncing files to a developer's workstation. By crafting specific tar entries, an attacker can overwrite critical system files or place malicious executables in startup directories, potentially achieving remote code execution on the host machine. This poses a significant risk to development environments, as the synchronization utility operates with the privileges of the user running the DevSpace CLI.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized arbitrary file writes on a developer's local workstation. This can lead to full system compromise, exfiltration of sensitive source code or credentials present in the user environment, and the persistent installation of malicious software. The impact is significant given that the affected tool is typically used in trusted development environments where security controls might be relaxed compared to production infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the DevSpace CLI to a version later than 6.3.21 immediately to address the vulnerability in the tar archive extraction logic.\u003c/li\u003e\n\u003cli\u003eAudit developer workstations for unauthorized files created by the DevSpace binary within unexpected directories.\u003c/li\u003e\n\u003cli\u003eRestrict container access to only authorized and trusted images to mitigate the risk of a malicious container interacting with the sync stream.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T23:37:06Z","date_published":"2026-09-14T23:37:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-devspace-tar-traversal/","summary":"DevSpace versions 6.3.21 and earlier are vulnerable to a path traversal flaw during the in-pod sync process that allows arbitrary file writes on developer workstations.","title":"Path Traversal Vulnerability in DevSpace In-Pod Sync","url":"https://feed.craftedsignal.io/briefs/2026-09-devspace-tar-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - DevSpace (\u003c= 6.3.21)","version":"https://jsonfeed.org/version/1.1"}