Hulumi versions before v1.3.2 contain a vulnerability in their deployment SCP (Service Control Policy) template that allows attackers to bypass tag-on-create protections for hulumi:iac-role. The flaw enables malicious actors to circumvent intended IAM boundary restrictions through exploitation of the weakened SCP template in downstream deployments. This represents a significant privilege escalation risk in cloud infrastructure-as-code environments. The vulnerability affects all hulumi deployments using versions prior to v1.3.2. Organizations using hulumi for IaC deployments should upgrade to v1.3.2 or later immediately. The issue was disclosed via GitHub Security Advisories and VulnCheck, indicating coordinated disclosure. Exploitation could allow unauthorized access to cloud resources protected by IAM boundary controls.