George Jenkins
3 exploits
Active since Apr 2026
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVSS 4.4
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVSS 8.6
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVSS 7.8