vulnerability in k8sgpt project
Author: ankitdnCreated Jul 11, 2025Updated Sep 16, 2026
Labelsbugcriticalvulnerability
While working on k8sgpt project, I discovered that the helm.sh/helm/v3 package has a critical vulnerability related to code injection. It occurs when a malicious Chart.yaml is used in combination with a symlinked Chart.lock file.
Source: k8sgpt-ai/k8sgpt