CVE-2026-35204 is a path traversal vulnerability in Helm, the Kubernetes package manager for Charts. It affects Helm versions 4.0.0 through 4.1.3. A specially crafted Helm plugin can abuse the plugin.yaml metadata, specifically the version field, by including POSIX dot-dot path separators such as '/../'. When the malicious plugin is installed or updated, Helm may use this attacker-controlled path component and write the contents of the plugin to an arbitrary filesystem location outside the intended plugin directory. The issue is therefore an arbitrary file write condition caused by improper path validation during plugin installation or update processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-35204, described as a Helm plugin path traversal / arbitrary file write issue affecting Helm 4.0.0 through 4.1.3. The repo contains one executable code file (CVE-2026-35204.py), a README with bilingual documentation and usage examples, and a .gitignore. The main exploit capabilities are: (1) checking the locally installed Helm version by invoking 'helm version --short'; (2) generating a malicious Helm plugin directory that contains a crafted plugin.yaml, an executable install.sh, and a benign-looking README; and (3) scanning an existing plugin directory for traversal markers such as '../' and suspicious sensitive paths. The exploit is primarily a generator for a malicious plugin rather than an automated remote exploitation tool. Operationally, the generated plugin abuses Helm’s plugin installation/update behavior to write attacker-controlled content to an arbitrary filesystem path chosen with --target. The default target is ~/.bashrc, which can lead to command execution when a new shell starts. The payload is customizable with --payload and examples include fetching and executing a remote shell script. The generated install.sh uses traversal-style path construction ('../' * 5 plus the stripped target path), while plugin.yaml also embeds an install hook that writes directly to the target path. Attack surface is local/file-based rather than direct network exploitation: a victim must install the malicious plugin on a vulnerable Helm installation. The README documents likely post-write targets such as ~/.ssh/authorized_keys, /etc/systemd/system/, and /etc/cron.d/ for persistence or access. Overall, this is a valid exploit PoC with basic but functional payload customization, making it OPERATIONAL rather than a simple detection script.
This repository is a small, working proof-of-concept for CVE-2026-35204 affecting Helm plugin installation. The repo contains four files: a README explaining the vulnerability and expected behavior, a crafted plugin.yaml carrying the malicious traversal payload in the version field, a plugin descriptor with a harmless echo command, and a Bash entry-point script at scripts/poc.sh that automates packaging, hosting, exploitation, verification, and cleanup. The exploit capability is limited but real: it does not achieve arbitrary extraction of plugin contents or overwrite arbitrary files directly via extraction, but it does cause Helm's HTTP plugin installer to write the downloaded plugin archive to an attacker-influenced filesystem path outside the intended Helm plugins directory. The PoC demonstrates this by causing the archive to be written as ~/.ssh/pwn3d.tgz. The extracted plugin contents still land in Helm's normal plugin directory. Operational flow: the script creates evil.tar.gz from plugin.yaml and scripts/, starts a local Python HTTP server on port 13037, then runs 'helm plugin install http://0.0.0.0:13037/evil.tar.gz --verify=false'. Because plugin.yaml sets version to '../../../../../../.ssh/pwn3d', Helm constructs a tarball filename/path that traverses out of the plugins directory. The script then verifies the presence of ~/.ssh/pwn3d.tgz, lists Helm cache and plugin directories, runs the installed plugin, and removes artifacts. This is not part of a major exploit framework. It is a standalone Bash/YAML PoC with a basic hardcoded payload and local HTTP serving, so OPERATIONAL is the best maturity fit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specially crafted Helm plugin can cause arbitrary file writes. The reference assigns this vulnerability a CVSS v3 base score of 8.6 and indicates proof-of-concept exploit maturity.
An arbitrary file write/path traversal vulnerability in Helm plugin handling affecting Helm versions 4.0.0 through 4.1.3, where a crafted plugin can cause Helm to write plugin contents to an arbitrary filesystem location.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.