CVE-2026-82862

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:17

Updated : 2026-09-01 15:17


NVD link : CVE-2026-82862

Mitre link : CVE-2026-82862

CVE.ORG link : CVE-2026-82862


JSON object : View

Products Affected

No product.

CWE
CWE-426

Untrusted Search Path