← Terug naar overzicht

CVE-2026-82862 affects Hulumi versions prior to v1.3.2, where the threat-model helper script is resolved from an unsafe root directory. This flaw allows workspace files to shadow the intended helper script, enabling attackers to place malicious files in the workspace. When a local skill is executed, the malicious file is run instead of the legitimate helper script, resulting in arbitrary code execution. The vulnerability is classified as high severity. A fix is available in Hulumi v1.3.2 and later. Users are advised to upgrade immediately to mitigate the risk. The issue has been documented in both the GitHub Security Advisory and VulnCheck advisories.

Affected products

  • Hulumi

Related CVE's

  • CVE-2026-82862

Categories

  • Security Tools
  • Supply Chain & Dependencies