← Terug naar overzicht

CVE-2026-82862 affects Hulumi versions before v1.3.2, where the threat-model helper script is resolved from an unsafe root directory. This flaw allows workspace files to shadow the intended helper script, enabling attackers to place malicious files in the workspace. When a local skill execution occurs, the malicious file is executed instead of the legitimate helper script, resulting in arbitrary code execution. The vulnerability is classified as high severity. Users are advised to upgrade to Hulumi v1.3.2 or later to remediate the issue. The advisory is referenced by both the GitHub Security Advisories and VulnCheck.

Affected products

  • Hulumi

Related CVE's

  • CVE-2026-82862

Categories

  • Supply Chain & Dependencies
  • Zero-Day Vulnerabilities