VYPR

hulumi

by Hulumi

CVEs (5)

  • CVE-2026-82859CriAug 31, 2026
    risk 0.64cvss 9.8epss

    hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.

  • CVE-2026-82858CriAug 31, 2026
    risk 0.64cvss 9.8epss

    @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe…

  • CVE-2026-82857CriAug 31, 2026
    risk 0.64cvss 9.8epss

    hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent…

  • CVE-2026-82862HigAug 31, 2026
    risk 0.55cvss 8.4epss

    Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

  • CVE-2026-82863LowAug 31, 2026
    risk 0.14cvss 3.3epss

    @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.