CVE-2026-82862

Source
https://cve.org/CVERecord?id=CVE-2026-82862
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82862.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82862
Aliases
  • GHSA-mjcg-x5mr-27ww
Published
2026-08-31T08:46:33.895Z
Modified
2026-09-03T03:30:31.365473427Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
Details

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82862.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-426"
    ]
}
References

Affected packages

Git / github.com/kerberosmansour/hulumi

Affected ranges

Type
GIT
Repo
https://github.com/kerberosmansour/hulumi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.2"
        },
        {
            "fixed": "v1.3.2"
        }
    ]
}

Affected versions

v1.*
v1.2.0
v1.3.0
v1.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82862.json"