#VU125577 Improper Verification of Cryptographic Signature in Helm - CVE-2026-35205
Published: April 9, 2026
Helm
The Helm Project
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper signature verification in the plugin installation and update verification logic when installing or updating a plugin with signature verification required and the provenance file is missing. A remote attacker can provide a specially crafted unsigned plugin missing the .prov file to execute arbitrary code.
Plugin hooks in the installed plugin are executed as designed, and user interaction is required.