Hunting Helm Template And Values Injection

Hunt injection through Kubernetes packaging templates and their values: an untrusted value rendered into a manifest without quoting so it injects YAML structure, a value that flows into a container command, an annotation, or an RBAC rule and grants more than intended, and a chart that renders privileged security context or host access from a caller-supplied value. Covers Helm-style templating where a values file or a user-supplied override is rendered into Kubernetes manifests, and where an unescaped or unconstrained value becomes structure, a command, or a permission. Use when charts render manifests from values that a tenant, a pipeline, or a user can influence. The untrusted value rendered into the manifest is the source, the template render is the sink, and the injected YAML structure or widened permission is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-helm-template-and-values-injection commit c0b531e8d3

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-helm-template-and-values-injection