← Back to overview

CVE-2026-82858 affects @hulumi/drift versions before 1.3.2, where the library accepts externally supplied execute plans without sufficient provenance validation. This flaw allows untrusted reconciliation input to be treated as trusted, enabling attackers to supply malicious execute plans. By doing so, attackers can bypass security checks and perform unsafe reconciliation operations. The vulnerability is classified as high severity. Users are advised to upgrade to version 1.3.2 or later to mitigate the risk. The issue was disclosed via GitHub Security Advisories and VulnCheck.

Affected products

  • '@hulumi/drift

Related CVE's

  • CVE-2026-82858

Categories

  • Supply Chain & Dependencies
  • Web Technologies