CVE-2026-82862
Received Received - Intake

Hulumi Local Skill Arbitrary Code Execution via Unsafe Script Resolution

Vulnerability report for CVE-2026-82862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hulumi hulumi to 1.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Hulumi versions before v1.3.2 have a vulnerability where helper scripts are resolved from an unsafe root directory. This allows workspace files to shadow the intended helper script, enabling attackers to place malicious files in the workspace. These files can then execute arbitrary code during local skill execution.

Detection Guidance

Check Hulumi version with 'hulumi --version' or inspect installed package metadata. Compare against v1.3.2. Look for unexpected helper scripts in workspace directories that may shadow the intended threat-model helper.

Impact Analysis

This vulnerability allows attackers to execute arbitrary code on your system by placing malicious files in the workspace. This could lead to unauthorized access, data theft, or system compromise during local skill execution.

Mitigation Strategies

Upgrade Hulumi to version 1.3.2 or later immediately. Remove any suspicious files in workspace directories that could shadow helper scripts. Verify helper script resolution paths after upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart