Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17943
http://www.hat-squad.com/en/000077.html