CVE-2026-82862: Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hulumito a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users running Hulumi versions before 1.3.2 are exposed when they perform local skill execution in a workspace that an attacker can populate with files.
What does an attacker need to exploit it?
The attacker needs the ability to place a malicious file in the target workspace. No privileges or user interaction are required according to the supplied vector.
How can the issue be remediated?
Upgrade Hulumi to version 1.3.2 or later. Until upgrading is possible, do not execute local skills in workspaces containing untrusted or attacker-controlled files.
How can I determine whether I may be affected?
Check whether the installed Hulumi version is earlier than 1.3.2 and whether local skills are executed against workspaces that may contain untrusted files.