CVE-2026-82862CWE-426

CVE-2026-82862

High · published August 31, 2026

CVSS v3.1
8.4
EPSS
0%
Percentile
3.0
In the wild
Unconfirmed
What it is

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.

The record
Technical detail
CVSS v3.1
8.4 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.6 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00131 · 3.0th percentile
Weakness
CWE-426 · Untrusted Search Path
Published
2026-08-31T13:17Z
References (2)
EPSS history
Timeline
  • 01 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 31 AUG 08:46Z
    Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
    cvelistv5