PT-2026-38264 · Devspace · Devspace

·

CVE-2026-42283

·

Published

2026-05-06

·

Updated

2026-07-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DevSpace versions prior to 6.3.21
Description The UI server WebSocket accepts connections from all origins by default, exposing several endpoints. A malicious website visited by a developer using a browser can establish a cross-origin WebSocket connection to 'ws://127.0.0.1:8090'. This allows unauthorized access to the following endpoints:
  • '/api/logs' to stream real-time pod logs
  • '/api/enter' to open an interactive shell inside the running pod
  • '/api/command' to execute pre-defined pipeline commands
Recommendations Update to version 6.3.21 or later.

Exploit

Fix

Missing Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42283
GHSA-HQWM-7X7X-8379
GO-2026-5433
OPENSUSE-SU-2026:21483-1

Affected Products

Devspace