Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm
{ "url": "https://pkg.go.dev/vuln/GO-2025-3802", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "Manager.Build", "Manager.Update", "writeLock" ], "path": "helm.sh/helm/v3/pkg/downloader" } ] }