VDB

RHSA-2025:16535

RHSA-2025:16535 PUBLISHED CVSS 8.5 HIGH

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symbolic link to an executable file, such as a shell script, and a user attempts to update the dependencies, the crafted content is written to the symlinked file and executed. This can lead to local code execution on the system. This issue has been patched in Helm version 3.18.4, and users should update to this version to mitigate the risk.

Risk Scores

CVSS 3.1
8.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/openshift4/ztp-site-generate-rhel8@sha256:a26870f0981a8f939a0ec7e2cbf794f3f4b7121802474a79570bdb44e61e2a2a_amd64 as a component of Red Hat OpenShift Container Platform 4.19*

Timeline

  • Sep 23, 2025 CVE Published
  • Jul 26, 2026 CVE Updated
  • Jul 26, 2026 Distribution Patch
  • Jul 26, 2026 Distribution Patch
  • Jul 26, 2026 Security Advisory
  • Jul 26, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›