VDB
RHSA-2025:16535
RHSA-2025:16535
PUBLISHED
CVSS 8.5 HIGH
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symbolic link to an executable file, such as a shell script, and a user attempts to update the dependencies, the crafted content is written to the symlinked file and executed. This can lead to local code execution on the system. This issue has been patched in Helm version 3.18.4, and users should update to this version to mitigate the risk.
Risk Scores
CVSS 3.1
8.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ztp-site-generate-rhel8@sha256:a26870f0981a8f939a0ec7e2cbf794f3f4b7121802474a79570bdb44e61e2a2a_amd64 as a component of Red Hat OpenShift Container Platform 4.19 | * |
Timeline
- Sep 23, 2025 CVE Published
- Jul 26, 2026 CVE Updated
- Jul 26, 2026 Distribution Patch
- Jul 26, 2026 Distribution Patch
- Jul 26, 2026 Security Advisory
- Jul 26, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:16535 advisory
- https://access.redhat.com/security/cve/CVE-2025-53547 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16535.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2378905 issue
- https://www.cve.org/CVERecord?id=CVE-2025-53547 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-53547 advisory
- https://github.com/helm/helm/commit/4b8e61093d8f579f1165cdc6bd4b43fa5455f571 advisory
- https://github.com/helm/helm/security/advisories/GHSA-557j-xg8c-q2mm advisory