{"id":"CVE-2020-4053","aliases":["GHSA-qq3j-xp49-j73f","BIT-helm-2020-4053"],"title":"Plugin archive directory traversal in Helm","summary":"Plugin archive directory traversal in Helm","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","vendor":"helm","product":"helm.sh/helm/v3","ecosystem":"go","affected":["helm.sh/helm/v3 >= 3.0.0, < 3.2.4"],"patched":["helm.sh/helm/v3 3.2.4"],"published":"2021-06-23","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qq3j-xp49-j73f","references":[{"url":"https://github.com/helm/helm/security/advisories/GHSA-qq3j-xp49-j73f"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4053"},{"url":"https://github.com/helm/helm/pull/8317"},{"url":"https://github.com/helm/helm/commit/0ad800ef43d3b826f31a5ad8dfbb4fe05d143688"},{"url":"https://github.com/helm/helm/commit/b6bbe4f08bbb98eadd6c9cd726b08a5c639908b3"},{"url":"https://github.com/helm/helm/releases/tag/v3.2.4"}],"tags":["osv","go"],"epss":0.01458,"epssPercentile":0.71959,"ingestedAt":"2026-07-09T18:56:36.703Z","slug":"CVE-2020-4053","body":"## Overview\n\nThe Helm core maintainers have identified an information disclosure\nvulnerability in Helm 3.0.0-3.2.3. \n\n### Impact\n\nA traversal attack is possible when installing Helm plugins from a tar\narchive over HTTP.  It is possible for a malicious plugin author to inject a relative\npath into a plugin archive, and copy a file outside of the intended directory.\n\nTraversal Attacks are a form of a Directory Traversal that can be exploited by\nextracting files from an archive. The premise of the Directory Traversal\nvulnerability is that an attacker can gain access to parts of the file system\noutside of the target folder in which they should reside. The attacker can\nthen overwrite executable files and either invoke them remotely or wait for\nthe system or user to call them, thus achieving Remote Command Execution on\nthe victim's machine. The vulnerability can also cause damage by overwriting\nconfiguration files or other sensitive resources, and can be exploited on both\nclient (user) machines and servers.\n\nhttps://snyk.io/research/zip-slip-vulnerability\n\n### Specific Go Packages Affected\nhelm.sh/helm/v3/pkg/plugin/installer\n\n### Patches\n\nThis issue has been fixed in Helm 3.2.4 \n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the Helm repository](https://github.com/helm/helm/issues)\n* For security-specific issues, email us at [cncf-helm-security@lists.cncf.io](mailto:cncf-helm-security@lists.cncf.io)\n\n## Affected packages\n\n- `helm.sh/helm/v3 >= 3.0.0, < 3.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `helm.sh/helm/v3 3.2.4`","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":20.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}