← Back to overview

CVE-2026-82858 affects @hulumi/drift versions before 1.3.2, which accept externally supplied execute plans without sufficient provenance validation. This flaw allows untrusted reconciliation input to be treated as trusted, enabling attackers to supply malicious execute plans that bypass security checks. The vulnerability permits unsafe reconciliation operations to be performed without proper authorization or verification. The fix is available in version 1.3.2 and later. This is a supply chain/dependency risk for any project relying on the @hulumi/drift package. The issue is documented in the NVD, a GitHub security advisory, and a VulnCheck advisory. No active exploitation details are currently mentioned, but the nature of the flaw presents significant risk if exploited in automated infrastructure or CI/CD pipelines.

Affected products

  • '@hulumi/drift

Related CVE's

  • CVE-2026-82858

Categories

  • Supply Chain & Dependencies
  • Web Technologies