Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
Published: 2026-07-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hulumi is an open‑source toolkit that ships secure‑by‑default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, an attacker could bypass policy packs by forging a Pulumi‑URN logical name. The flaw, classified as CWE‑693, involves improper authentication or authorization checks that allow crafted URNs to satisfy policy evaluation. It was remedied in version 1.4.0.

Affected Systems

The affected vendor is Kerberos Mansour, product Hulumi. All releases prior to version 1.4.0 are vulnerable. The patch providing protection was released as part of the 1.4.0 release.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. Hulumi is not listed in CISA’s KEV catalog. Based on the description, the attack vector appears to be a forgery of logical names within a Pulumi deployment, which would be exercised when the tool processes user‑specified resources. The attacker would need to supply a crafted Pulumi‑URN during deployment; the vulnerability is not exploitable over a network interface without such a deployment context.

Generated by OpenCVE AI on August 3, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hulumi to version 1.4.0 or later to apply the fix that prevents URN forging from bypassing policy packs.
  • Validate all Pulumi‑URN values in your deployment scripts to ensure they are not tampered with and conform to expected patterns.
  • Audit your existing Pulumi configurations and infrastructure to detect any unauthorized or forged URN usages that might have bypassed policy enforcement prior to the upgrade.

Generated by OpenCVE AI on August 3, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rhgj-6g2c-frmm @hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Kerberosmansour
Kerberosmansour hulumi
Vendors & Products Kerberosmansour
Kerberosmansour hulumi

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
Title Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Kerberosmansour Hulumi
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-24T19:16:19.349Z

Reserved: 2026-05-20T18:15:53.577Z

Link: CVE-2026-48033

cve-icon Vulnrichment

Updated: 2026-07-24T19:16:15.347Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T19:16:58.340

Modified: 2026-07-28T16:17:16.127

Link: CVE-2026-48033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:00:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure