
A path traversal flaw (CVE-2026-35204) in `Helm` plugin metadata allows arbitrary file writes. Exercise caution with untrusted `Helm` plugins. #Helm #Kubernetes #CloudNative https://www.pulsepatch.io/posts/cve-2026-35204-helm-path-traversal
Post summary
The post discloses a new path traversal vulnerability (CVE-2026-35204) in Helm plugin metadata that permits arbitrary file writes, and offers a mitigation recommendation to avoid untrusted plugins.


