CVE-2026-82862 PUBLISHED

Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor kerberosmansour
Product hulumi
Versions Default: unaffected
  • affected from 0 to 1.3.2 (excl.)
  • Version 1.3.2 is unaffected

References

Problem Types

  • Untrusted Search Path CWE