In the library `helm.sh/helm/v3` version `3.10.2` was detected in `Golang binary` located at `/opt/asm/asm-installer` and is vulnerable to `CVE-2025-53547`, which exists in versions `< 3.17.4`. The vulnerability was found in GHSA-557j-xg8c-q2mm with vendor severity: `High` (awaiting NVD analysis, [CNA]CVE-2025-53547) severity: `High`). Note: If this library is owned by a 3rd party vendor (e.g. open source library), follow the vendor's release-notes to check remediation options.
Solution summary:
go get -u helm.sh/helm/v3
The vulnerability in the helm library used by the installer was fixed. The asm OPMS podman installer 25.2.28and later is not vulnerable.