CVE-2026-35204Disclosure(helm / helm)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch helm helm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. "/../". This vulnerability is fixed in 4.1.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • helm

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
helm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-13: 104-0904-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-131
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal flaw (CVE-2026-35204) in `Helm` plugin metadata allows arbitrary file writes. Exercise caution with untrusted `Helm` plugins. #Helm #Kubernetes #CloudNative https://www.pulsepatch.io/posts/cve-2026-35204-helm-path-traversal

    Post summary

    The post discloses a new path traversal vulnerability (CVE-2026-35204) in Helm plugin metadata that permits arbitrary file writes, and offers a mitigation recommendation to avoid untrusted plugins.

    0000037
    13 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35204 Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the con… https://www.cve.org/CVERecord?id=CVE-2026-35204

    Post summary

    The entry discloses a Helm plugin vulnerability affecting versions 4.0.0‑4.1.3 that allows improper file writes; no PoC, exploit code, or patch is provided.

    00000100
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35204 Arbitrary File Write Vulnerability in Helm 4.0.0 Through 4.1.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35204

    Post summary

    A new arbitrary file write vulnerability affecting Helm 4.0.0–4.1.3 has been disclosed, but no PoC, exploit, patch, or active exploitation information is included.

    0000029
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphelmhelm---

Explore more