Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
Published: 2026-07-24
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Hulumi occurs when AccountFoundation reuse paths silently downgrade the configuration of AWS GuardDuty and Security Hub prior to version 1.4.0, reducing the security posture of cloud deployments that rely on Hulumi’s secure‑by‑default components until the issue is patched in version 1.4.0.

Affected Systems

The affected product is the Hulumi open‑source cloud infrastructure toolkit published by kerberosmansour. Any deployment that uses a version earlier than 1.4.0 and includes AccountFoundation reuse paths within Pulumi scripts is impacted. Users that rely on the default secure configuration may find that GuardDuty and Security Hub protections are inadvertently weakened or disabled.

Risk and Exploitability

The CVSS score of 6.3 places the weakness in the medium severity range, while an EPSS score below 1 % indicates a low probability of active exploitation in the wild. However, because the downgrade occurs silently, automated CI/CD pipelines could unintentionally regress security services without operators noticing. The flaw is not listed in the CISA KEV catalog, but its effect on the integrity of security controls warrants prompt remediation. Based on the description, it is inferred that the attack vector most likely involves executing Pulumi templates that reuse AccountFoundation paths, thereby reducing the cloud environment's protected posture.

Generated by OpenCVE AI on August 3, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hulumi to version 1.4.0 or later, which applies the fix.
  • Audit existing Pulumi scripts for AccountFoundation reuse paths and remove or replace them when an upgrade is not yet possible.
  • Verify that GuardDuty and Security Hub remain enabled after deployment and monitor their status to detect any accidental disabling.

Generated by OpenCVE AI on August 3, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cj8g-prcm-mfg5 @hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Kerberosmansour
Kerberosmansour hulumi
Vendors & Products Kerberosmansour
Kerberosmansour hulumi

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
Title Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

Kerberosmansour Hulumi
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-27T16:05:37.812Z

Reserved: 2026-05-20T18:15:53.577Z

Link: CVE-2026-48037

cve-icon Vulnrichment

Updated: 2026-07-27T16:05:32.205Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T19:16:58.897

Modified: 2026-07-28T16:17:16.127

Link: CVE-2026-48037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:00:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure