DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` and `Unzip()` functions in `pkg/archive/archive.go`. Downloads and extracts archives from remote sources without path validation. Version 1.25.2 patches the issue.
References
| Link | Resource |
|---|---|
| https://github.com/ddev/ddev/releases/tag/v1.25.2 | Product Release Notes |
| https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg | Exploit Mitigation Vendor Advisory |
| https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg | Exploit Mitigation Vendor Advisory |
Configurations
History
11 May 2026, 20:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ddev/ddev/releases/tag/v1.25.2 - Product, Release Notes | |
| References | () https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg - Exploit, Mitigation, Vendor Advisory | |
| First Time |
Ddev ddev
Ddev |
|
| CPE | cpe:2.3:a:ddev:ddev:*:*:*:*:*:*:*:* |
22 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ddev/ddev/security/advisories/GHSA-x2xq-qhjf-5mvg - |
22 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 17:16
Updated : 2026-05-11 20:33
NVD link : CVE-2026-32885
Mitre link : CVE-2026-32885
CVE.ORG link : CVE-2026-32885
JSON object : View
Products Affected
ddev
- ddev
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
