CVE-2026-35204
HIGHHelm 4.0.0-4.1.3 Plugin Metadata - Arbitrary File Write
Title source: manualExploitation Summary
EIP tracks 3 public exploits for CVE-2026-35204. PoCs published by amnsecurity, HORKimhab, h3ck13r.
AI-analyzed exploit summary This repository provides a functional proof-of-concept exploit for CVE-2026-35204, a path traversal vulnerability in Helm (versions 4.0.0-4.1.3) that allows arbitrary file writes via malicious plugin installation. The exploit generates a crafted Helm plugin with traversal sequences in plugin.yaml to write attacker-controlled payloads to arbitrary filesystem locations.
Description
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. "/../". This vulnerability is fixed in 4.1.4.
Exploits (3)
This repository provides a functional proof-of-concept exploit for CVE-2026-35204, a path traversal vulnerability in Helm (versions 4.0.0-4.1.3) that allows arbitrary file writes via malicious plugin installation. The exploit generates a crafted Helm plugin with traversal sequences in plugin.yaml to write attacker-controlled payloads to arbitrary filesystem locations.
The repository contains only a markdown file describing CVE-2026-35204, a path traversal vulnerability in Helm's plugin metadata version field, but provides no actual exploit code. Instead, it links to external sources (GitHub repo and encrypted ZIP backup) for PoCs, which is a red flag for potential social engineering.
The repository contains only a README.md and LICENSE file with no actual exploit code, technical details, or vulnerability analysis. It serves as a placeholder with no functional content.
References (7)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H