CVE-2020-11013
Helm vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2020-11013) is an information disclosure vulnerability discovered in Helm versions 3.1.0-3.1.2. The issue was identified by the Helm core maintainers and disclosed on April 22, 2020. The vulnerability affects the lookup template function introduced in Helm v3, which could allow unintended cluster access during template rendering operations (Helm Advisory).

Technical details

The vulnerability stems from the lookup template function's behavior, which connects to the cluster during helm template and helm install|update|delete|rollback --dry-run operations without notifying the user. This behavior contradicts the documented functionality of helm template, which states it should not attach to a remote cluster. The issue was patched in versions 3.1.3 and 3.2.0 (Helm Advisory).

Impact

A malicious chart author could exploit this vulnerability by injecting a lookup function into a chart that, when rendered through helm template, performs unauthorized lookups against the cluster specified in a user's KUBECONFIG file. The retrieved information could then be exposed through the helm template output (Helm Advisory).

Exploitability

The vulnerability only impacts Helm 3.1.x versions, while Helm 2 and 3.0.x remain unaffected. The exploit requires a malicious chart to be processed using the helm template command, with the user having a valid KUBECONFIG file pointing to a cluster (Helm Advisory).

Mitigation and workarounds

Several workarounds are available: running helm lint on untrusted charts (which will fail if the lookup function is present), setting KUBECONFIG to point to an empty configuration file, or manually analyzing chart templates for the presence of lookup functions. The vulnerability has been permanently fixed in Helm versions 3.1.3 and 3.2.0 (Helm Advisory).

Community reactions

The vulnerability was addressed promptly in the Helm v3.2.0 release, which included the security fix along with other feature improvements. The issue was treated as a low-severity security concern and was handled through proper disclosure channels (Helm Release).

Additional resources


SourceThis report was generated using AI

Related Helm vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-37236CRITICAL9.8
  • Grafana logoGrafana
  • grafana-stackdriver
NoYesAug 28, 2026
CVE-2026-84445HIGH8.7
  • cAdvisor logocAdvisor
  • conftest-fips
NoYesSep 14, 2026
CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • cloud-provider-aws-1.35
NoYesSep 01, 2026
CVE-2026-53495MEDIUM6.8
  • Packer logoPacker
  • chaos-mesh
NoYesSep 14, 2026
CVE-2026-84303MEDIUM6.3
  • New Relic Agent logoNew Relic Agent
  • db-operator
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management