cvss 8.5
how bad it is if exploited, out of 10
epss 0.40%
chance of exploitation in the next 30 days
xyz score 3.7
CyberXYZ composite, out of 10
fig. 01 — GHSA-557j-xg8c-q2mm, the advisory selected below
// advisories GHSA-557j-xg8c-q2mm HIGH GHSA-r53h-jv2g-vpx6 HIGH GHSA-53c4-hhmh-vw5q HIGH GHSA-6rx9-889q-vv2r HIGH GHSA-67fx-wx78-jx33 HIGH GHSA-cjjc-xp8v-855w HIGH GHSA-q8q8-93cv-v6h8 HIGH GHSA-f9f8-9pmf-xv68 MEDI GHSA-9h84-qmv7-982p MEDI GHSA-4hfp-h4cw-hj8p MEDI GHSA-5xqw-8hwv-wg92 MEDI GHSA-jw44-4f3j-q396 MODE GHSA-v53g-5gjp-272r MEDI GHSA-7hfp-qfw3-5jxh MEDI GHSA-56hp-xqp3-w2jf MODE GHSA-c38g-469g-cmgx MEDI GHSA-qq3j-xp49-j73f LOW GHSA-9vp5-m38w-j776 LOW GHSA-m54r-vrmv-hw33 LOW GHSA-c52f-pq47-2r9j LOW GHSA-jm56-5h66-w453 LOW
GHSA-557j-xg8c-q2mm HIGH CVE-2025-53547 A Helm contributor discovered that a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated.
Affected >=0, <3.18.4 Fixed in 3.17.4 Weakness CWE-94 Published 2025-07-08 Source github GHSA NVD MITRE
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2025-08-14. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page