DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` and `Unzip()` functions in `pkg/archive/archive.go`. Downloads and extracts archives from remote sources without path validation. Version 1.25.2 patches the issue.
References
| Link | Resource |
|---|---|
| https://github.com/ddev/ddev/releases/tag/v1.25.2 | Product Release Notes |
| https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg | Exploit Mitigation Vendor Advisory |
| https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-22 17:16
Updated : 2026-06-17 10:36
NVD link : CVE-2026-32885
Mitre link : CVE-2026-32885
CVE.ORG link : CVE-2026-32885
JSON object : View
Products Affected
ddev
- ddev
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
