GHSA-qwm3-f9wh-qp63CriticalCVSS 9.8

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create...

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.

🔗 References (4)