PT-2026-83735 · Npm · @Hulumi/Drift
CVE-2026-82858
·
Published
2026-05-21
·
Updated
2026-09-01
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@hulumi/drift versions prior to 1.3.2
Description
Insufficient provenance validation allows the software to accept externally supplied execute plans, causing untrusted reconciliation input to be treated as trusted. This allows attackers to provide malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
Recommendations
Upgrade @hulumi/drift to version 1.3.2 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Hulumi/Drift