Vulnerability in Hulumi Affects Versions Prior to 1.3.2
CVE-2026-82862

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82862?

Hulumi versions before 1.3.2 contain a vulnerability that allows workspace files to shadow the intended threat-model helper script. This flaw can be exploited by attackers who place malicious files in the workspace, enabling them to execute arbitrary code during local skill execution. It is essential for users to update to the latest version to mitigate this risk.

Affected Version(s)

hulumi 0 < 1.3.2

hulumi 1.3.2

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.