Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-15187

19
FAUCET Score

CVE-2020-15187 describes a local execution vulnerability in Helm versions prior to 2.16.11 and 3.3.2. An attacker with write access to a plugin's git repository or archive, or via a Man-in-the-Middle attack on an insecure connection, could modify install hooks to achieve local code execution. Rated Medium severity (CVSS 4.7), this vulnerability requires high privileges (PR:H) and has a low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.16.11CPE matchmatch criteria
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.3.2CPE matchmatch criteria
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.0LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.52%
Probability of exploitation in next 30 days
EPSS Percentile
71.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0152 is in the 79th percentile among its peer group of 3,565 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: helm.sh/helm/v3Fixed in: 3.3.2
gopatch availablevia ghsa
Product: helm.sh/helmFixed in: 2.16.11
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: helm

Vendor Advisories (2)

goGHSA-c52f-pq47-2r9jlow

plugin.yaml file allows for duplicate entries in helm

May 24, 2021
redhatCVE-2020-15187Moderate

helm: write access to the git repository or plugin archive causing causing a local execution attack

Sep 18, 2020

References

github.com / helm/helm/commit/6aab63765f99050b115f0aec3d6350c85e8da946
github.com / helm/helm/commit/ac7c07c37d87e09797f714fb57aa5e9cb99d9450
github.com / helm/helm/commit/b0296c0522e837d65f944beefa3fb64fd08ac304
github.com / helm/helm/commit/c8d6b01d72c9604e43ee70d0d78fadd54c2d8499
github.com / helm/helm/commit/d9ef5ce8bad512e325390c0011be1244b8380e4b
PatchThird Party Advisory
github.com / helm/helm/commit/f2ede29480b507b7d8bb152dd8b6b86248b00658
github.com / helm/helm/security/advisories/GHSA-c52f-pq47-2r9j
Third Party Advisory