Helm disclosed two high-severity flaws in its plugin handling that affect versions 4.0.0 through 4.1.3, including CVE-2026-35204 and CVE-2026-35205. The first bug is a path traversal issue in plugin metadata that lets a specially crafted plugin use ../ sequences in the version field of plugin.yaml to write files outside the intended Helm plugin directory during installation or update, creating a risk of arbitrary file write on the local filesystem.
The second flaw causes Helm to fail open on plugin provenance checks, allowing installation of plugins without a .prov file even when signature verification is required. Both issues were addressed in Helm 4.1.4, with fixes published through the project release and corresponding GitHub security advisories, and users running affected Helm 4 releases are advised to upgrade to the patched version.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The two Helm vulnerabilities were publicly disclosed with CVE entries and GitHub security advisory references. The disclosures documented affected versions, technical impact, and the availability of fixes in Helm 4.1.4.
Helm fixed both CVE-2026-35204 and CVE-2026-35205 in version 4.1.4. The update addressed arbitrary file write outside the plugin directory via crafted plugin metadata and improper installation of unsigned plugins when provenance files are absent.
Security reports were received for two Helm flaws affecting versions 4.0.0 through 4.1.3: a path traversal issue in plugin metadata version handling (CVE-2026-35204) and a fail-open plugin verification issue when a .prov file is missing (CVE-2026-35205).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.