Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-31 09:17
Updated : 2026-09-01 15:17
NVD link : CVE-2026-82862
Mitre link : CVE-2026-82862
CVE.ORG link : CVE-2026-82862
JSON object : View
Products Affected
No product.
CWE
CWE-426
Untrusted Search Path
