CVE-2026-82862CWE-426
CVE-2026-82862
High · published August 31, 2026
What it is
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
The record
Technical detail
- CVSS v3.1
- 8.4 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- 8.6 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00131 · 3.0th percentile
- Weakness
- CWE-426 · Untrusted Search Path
- Published
- 2026-08-31T13:17Z
References (2)
EPSS history
Timeline