{"id":"CVE-2020-15184","aliases":["GHSA-9vp5-m38w-j776","BIT-helm-2020-15184"],"title":"Aliases are never checked in helm","summary":"Aliases are never checked in helm","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","vendor":"helm","product":"helm.sh/helm/v3","ecosystem":"go","affected":["helm.sh/helm/v3 >= 3.0.0, < 3.3.2","helm.sh/helm < 2.16.11"],"patched":["helm.sh/helm/v3 3.3.2","helm.sh/helm 2.16.11"],"published":"2021-05-24","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9vp5-m38w-j776","references":[{"url":"https://github.com/helm/helm/security/advisories/GHSA-9vp5-m38w-j776"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15184"},{"url":"https://github.com/helm/helm/commit/6aab63765f99050b115f0aec3d6350c85e8da946"},{"url":"https://github.com/helm/helm/commit/e7c281564d8306e1dcf8023d97f972449ad74850"},{"url":"https://github.com/helm/helm"}],"tags":["osv","go"],"epss":0.01029,"epssPercentile":0.62118,"ingestedAt":"2026-07-09T18:56:36.296Z","slug":"CVE-2020-15184","body":"## Overview\n\n### Impact\n\nDuring a security audit of Helm's code base, security researchers at Trail of Bits identified a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart.\n\n### Patches\n\nThis issue has been patched in Helm 3.3.2 and 2.16.11\n\n### Specific Go Packages Affected\nhelm.sh/helm/v3/pkg/chartutil\n\n### Workarounds\n\nManually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.\n\n## Affected packages\n\n- `helm.sh/helm/v3 >= 3.0.0, < 3.3.2`\n- `helm.sh/helm < 2.16.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `helm.sh/helm/v3 3.3.2`\n- `helm.sh/helm 2.16.11`","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":20.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}