PatchSiren

devspace CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH devspace CVE published 2026-09-14

CVE-2026-91200

CVE-2026-91200 is a path traversal vulnerability in DevSpace, a tool used for syncing files between a developer workstation and a Kubernetes pod. The vulnerability allows an attacker to write arbitrary files on the developer workstation by streaming tar entries with traversal sequences. This can lead to code execution on the workstation. The vulnerability exists due to inadequate handling of tar entry nam [truncated]