@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-31 09:17
Updated : 2026-08-31 20:52
NVD link : CVE-2026-82858
Mitre link : CVE-2026-82858
CVE.ORG link : CVE-2026-82858
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
