CVE-2025-53547High· 8.5▾ MidnightPoC availableA command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 46.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
Last analysed / modified upstream
1 GitHub repo (last check)
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symbolic link to an executable file, such as a shell script, and a user attempts to update the dependencies, the crafted content is written to the symlinked file and executed. This can lead to local code execution on the system. This issue has been patched in Helm version 3.18.4, and users should update to this version to mitigate the risk.
helm.sh/helm/v3: Helm Chart Code Execution — rated Important by Red Hat. Released 2025-07-08, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/errata/RHSA-2025:18744 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:
https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/errata/RHSA-2025:16113 For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro https://access.redhat.com/errata/RHSA-2025:18278
Workarounds / mitigations:
Affected packages:
helm.sh/helm/v3 >= 3.18.0-rc.1, < 3.18.4helm.sh/helm/v3 < 3.17.4Patched in:
helm.sh/helm/v3 3.18.4helm.sh/helm/v3 3.17.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86320High· 7.8A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true
CVE-2025-71408High· 7.0nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)
CVE-2025-66448High· 7.5vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)
CVE-2025-69262High· 7.5pnpm is a package manager
CVE-2026-91203Medium· 6.0A flaw was found in cockpit-files
CVE-2026-92747Medium· 5.0A flaw was found in `cockpit-machines`