Impact
The vulnerability in Hulumi occurs when AccountFoundation reuse paths silently downgrade the configuration of AWS GuardDuty and Security Hub prior to version 1.4.0, reducing the security posture of cloud deployments that rely on Hulumi’s secure‑by‑default components until the issue is patched in version 1.4.0.
Affected Systems
The affected product is the Hulumi open‑source cloud infrastructure toolkit published by kerberosmansour. Any deployment that uses a version earlier than 1.4.0 and includes AccountFoundation reuse paths within Pulumi scripts is impacted. Users that rely on the default secure configuration may find that GuardDuty and Security Hub protections are inadvertently weakened or disabled.
Risk and Exploitability
The CVSS score of 6.3 places the weakness in the medium severity range, while an EPSS score below 1 % indicates a low probability of active exploitation in the wild. However, because the downgrade occurs silently, automated CI/CD pipelines could unintentionally regress security services without operators noticing. The flaw is not listed in the CISA KEV catalog, but its effect on the integrity of security controls warrants prompt remediation. Based on the description, it is inferred that the attack vector most likely involves executing Pulumi templates that reuse AccountFoundation paths, thereby reducing the cloud environment's protected posture.
OpenCVE Enrichment
Github GHSA