CVE-2026-82862
nicheUntrusted Search Path in Hulumi Allows Code Execution via Workspace Files
CVE-2026-82862 is an untrusted search path flaw (CWE-426) in Hulumi, a tool that executes local skills including a threat-model helper script; in versions before v1.3.2, the helper script is resolved from an unsafe root, so files in the current workspace can shadow (override) the legitimate helper. An attacker who can place malicious files in a workspace — for example through a cloned repository, shared project folder, or other attacker-controlled workspace content — can have that malicious file executed in place of the intended helper when a user runs the affected skill locally. Successful execution gives the attacker arbitrary code execution on the victim's machine with the privileges of the user running Hulumi, with high impact on confidentiality, integrity, and availability (CVSS 4.0 score 8.6). Anyone running an affected version of Hulumi (all versions prior to v1.3.2) and executing skills in workspaces that may contain untrusted files is affected. There is no known exploitation, no public proof-of-concept, a low 0.1% EPSS probability of exploitation in the next 30 days, and the issue is not listed in CISA KEV.
What to do: Upgrade Hulumi to v1.3.2 or later. As an interim mitigation, avoid running skills in workspaces containing files from untrusted sources, and check workspaces for unexpected files at the path where the threat-model helper script is resolved before execution. Treat cloned repositories and shared workspaces as untrusted input until patched.
| Hulumi | all versions before v1.3.2 (< 1.3.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
- Weakness
- CWE-426
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.