StackRadar

CVE-2025-53547

High

Advisory

Published 8 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

Helm vulnerable to Code Injection through malicious chart.yaml content

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
helm.sh/helm/v3golangv0.0.0-20221012195806-9f88ccb6aee4, v0.0.0-20221214143859-835b7334cfe2, v0.0.0-20230113165805-472c5736ab01, v0.0.0-20230308205603-912ebc1cd10d+68 more3.17.4, 3.18.4160
OSV records
GHSA-557j-xg8c-q2mm
Also known as
BIT-helm-2025-53547, GO-2025-3802

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
helm.sh/helm/v3@v3.11.3
3.17.4
goharbor/harbor-jobservice:v2.9.039435daedd0c
helm.sh/helm/v3@v3.11.3
3.17.4
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
helm.sh/helm/v3@v3.12.1
3.17.4

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
helm.sh/helm/v3@v3.12.1
3.17.4

Open the chart page →

2,505
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
helm.sh/helm/v3@v3.14.3
3.17.4

Open the chart page →

1,360
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
helm.sh/helm/v3@v3.14.2
3.17.4

Open the chart page →

2,477
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
helm.sh/helm/v3@v3.11.0
3.17.4

Open the chart page →

6,232
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-53547.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
helm.sh/helm/v3@v0.0.0-20230113165805-472c5736ab01
3.17.4

Open the chart page →

13,677

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
helm.sh/helm/v3@v3.12.2
3.17.4
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
helm.sh/helm/v3@v3.11.3
3.17.4
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
helm.sh/helm/v3@v3.14.4
3.17.4
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
helm.sh/helm/v3@v3.8.0
3.17.4
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
helm.sh/helm/v3@v3.7.1
3.17.4
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
helm.sh/helm/v3@v3.3.4
3.17.4
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
helm.sh/helm/v3@v3.6.3
3.17.4
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
helm.sh/helm/v3@v3.6.3
3.17.4
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
helm.sh/helm/v3@v0.0.0-20231012132431-3547a4b5bf5e
3.17.4
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
helm.sh/helm/v3@v3.7.0
3.17.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.