在 v1.3.2 之前的 Hulumi 版本中,威胁模型(threat-model)辅助脚本从一个不安全的根目录进行解析,这允许工作区中的文件“遮蔽”(shadow)原本应被使用的辅助脚本。攻击者可以在工作区中放置恶意文件,从而在本地技能(skill)执行过程中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kerberosmansour | hulumi | 0 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82859 | 9.8 CRITICAL | hulumi before v1.3.2 SCP Template Tag-on-Create Bypass |
| CVE-2026-82857 | 9.8 CRITICAL | hulumi before v1.3.2 Privilege Escalation via IAM Policy |
No comments yet