PT-2024-4076 · Helm+2 · Helm+2

Dominykas

·

Published

2024-02-14

·

Updated

2025-11-28

·

CVE-2024-25620

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Helm versions prior to 3.14.1
Description The issue is related to the Helm client or SDK saving a chart outside its expected directory based on changes in the relative path within the Chart.yaml file. This occurs when the chart's name includes a relative path change, which is not detected by validation and linting. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability allows a remote attacker to save a Helm chart outside its expected directory, potentially leading to unauthorized access or modifications. Technical details about exploitation include the use of relative path changes in the chart's name within the Chart.yaml file, which can lead to path traversal.
Recommendations For versions prior to 3.14.1, update to Helm v3.14.1 to resolve the issue. As a temporary workaround, check all charts used by Helm for path changes in their name as found in the Chart.yaml file, including dependencies.

Exploit

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-10258
ALT-PU-2025-1444
AZL-34355
AZL-34583
AZL-38023
BDU:2024-04524
BIT-HELM-2024-25620
CVE-2024-25620
GHSA-V53G-5GJP-272R
GO-2024-2554
OPENSUSE-SU-2024:13714-1
OPENSUSE-SU-2024_1137-1
OPENSUSE-SU-2025:15779-1
SUSE-RU-2024:4213-1
SUSE-SU-2024:1137-1
SUSE-SU-2024_1137-1
SUSE-SU-2025:20196-1
SUSE-SU-2025:20278-1

Affected Products

Alt Linux
Helm
Suse