HIGH 8.6 NVD
CVE-2026-82862
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attacke
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
References
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-mjcg-x5mr-27ww
- https://www.vulncheck.com/advisories/hulumi-before-1.3.2-helper-script-shadowing-via-works
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11521 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.