CVE Vulnerabilities

CVE-2025-53547

Improper Control of Generation of Code ('Code Injection')

Published: Jul 08, 2025 | Modified: Sep 03, 2025
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.5 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H
Ubuntu

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated and this file is written, can be crafted in a way that can cause execution if that same content were in a file that is executed (e.g., a bash.rc file or shell script). If the Chart.lock file is symlinked to one of these files updating dependencies will write the lock file content to the symlinked file. This can lead to unwanted execution. Helm warns of the symlinked file but did not stop execution due to symlinking. This issue has been resolved in Helm v3.18.4.

Weakness

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Software

Name Vendor Start Version End Version
Helm Helm * 3.17.4 (excluding)
Helm Helm 3.18.0 (including) 3.18.4 (excluding)
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-cli-container-v2.13.4-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-cluster-permission-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-governance-policy-addon-controller-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-governance-policy-framework-addon-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-grafana-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-multicluster-observability-addon-container-v2.13.4-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-must-gather-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-operator-bundle-container-v2.13.4-22 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-prometheus-config-reloader-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-prometheus-operator-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-indexer-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-v2-api-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-search-v2-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-siteconfig-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat acm-volsync-addon-controller-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat cert-policy-controller-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat cluster-backup-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat config-policy-controller-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat console-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat endpoint-monitoring-operator-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat governance-policy-propagator-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat grafana-dashboard-loader-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat insights-client-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat insights-metrics-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat klusterlet-addon-controller-container-v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat kube-rbac-proxy-container-v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat kube-state-metrics-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat memcached-exporter-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat metrics-collector-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicloud-integrations-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multiclusterhub-operator-container-v2.13.4-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-observability-operator-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-application-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-channel-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat multicluster-operators-subscription-operator-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat node-exporter-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat observatorium-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat observatorium-operator-container-v2.13.4-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat prometheus-alertmanager-container-v2.13.4-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat prometheus-container-v2.13.4-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rbac-query-proxy-container-v2.13.4-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-api-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-ocp-ui-rhel9:v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-periodic-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-ui-rhel9:v2.13.4-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/acm-flightctl-worker-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat rhacm2/memcached-rhel9:v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat search-collector-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat submariner-addon-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat thanos-container-v2.13.4-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 RedHat thanos-receive-controller-container-v2.13.4-11 *
Red Hat OpenShift Container Platform 4.16 RedHat registry.redhat.io/openshift4/ose-operator-sdk-rhel9:sha256:265ac97f0a4e57ca86108b399b26d734f4d8f0a1ca7418ebfece1c4988ea61d2 *
Red Hat OpenShift Container Platform 4.17 RedHat registry.redhat.io/openshift4/ose-operator-sdk-rhel9:sha256:b4d145dd4c58c63855b4b723e38a67a50eef2520cf8c55e644c38deea07d532e *

Potential Mitigations

  • Run your code in a “jail” or similar sandbox environment that enforces strict boundaries between the process and the operating system. This may effectively restrict which code can be executed by your product.
  • Examples include the Unix chroot jail and AppArmor. In general, managed code may provide some protection.
  • This may not be a feasible solution, and it only limits the impact to the operating system; the rest of your application may still be subject to compromise.
  • Be careful to avoid CWE-243 and other weaknesses related to jails.
  • Assume all input is malicious. Use an “accept known good” input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
  • When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, “boat” may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as “red” or “blue.”
  • Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code’s environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
  • To reduce the likelihood of code injection, use stringent allowlists that limit which constructs are allowed. If you are dynamically constructing code that invokes a function, then verifying that the input is alphanumeric might be insufficient. An attacker might still be able to reference a dangerous function that you did not intend to allow, such as system(), exec(), or exit().
  • For Python programs, it is frequently encouraged to use the ast.literal_eval() function instead of eval, since it is intentionally designed to avoid executing code. However, an adversary could still cause excessive memory or stack consumption via deeply nested structures [REF-1372], so the python documentation discourages use of ast.literal_eval() on untrusted data [REF-1373].

References