{"schema_version":"1.7.3","id":"GO-2023-1938","published":"2024-08-20T20:31:38Z","modified":"2026-03-03T04:53:59.593249Z","aliases":["CVE-2019-18658","GHSA-p5pc-m4q7-7qm9"],"summary":"Helm Unsafe Link Following in helm.sh/helm","details":"Helm Unsafe Link Following in helm.sh/helm","affected":[{"package":{"name":"helm.sh/helm","ecosystem":"Go","purl":"pkg:golang/helm.sh/helm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0+incompatible"},{"fixed":"2.15.2+incompatible"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-1938.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-p5pc-m4q7-7qm9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-18658"},{"type":"WEB","url":"https://helm.sh/blog/2019-10-30-helm-symlink-security-notice"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-1938"}}