OVERVIEW CVE-2026-35204 is a path traversal vulnerability affecting Helm versions 4.0.0 through 4.1.3, a widely-used package manager for Kubernetes applications. The vulnerability allows specially crafted Helm plugins to write arbitrary files to the filesystem when the plugin is installed or updated. The flaw exists in Helm's failure to properly validate the version field in plugin.yaml files, which can contain POSIX dot-dot path separators to bypass directory restrictions. The vulnerability has been remediated in version 4.1.4. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.6 (HIGH) with a local attack vector requiring minimal complexity and no special privileges, though user interaction is necessary. The impact is severe across confidentiality, integrity, and availability, as attackers can write malicious content to arbitrary locations on the affected system. This could enable code execution, configuration tampering, or system compromise depending on filesystem permissions and target locations. EXPLOITATION STATUS No active exploitation has been reported. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on industry hot lists. The EPSS score of 0.00012 indicates this threat ranks lower than 99.98% of all published CVEs in terms of predicted exploitation likelihood. However, organizations running Helm 4.0.0-4.1.3 should promptly upgrade to 4.1.4 to close this local attack surface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.1.4CPE matchmatch criteria | cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.