Impact
The vulnerability in @hulumi/policies versions prior to 1.3.2 undermines the administrator‑policy guardrail by not fully validating policy evidence. Attackers can craft admin‑equivalent IAM policy paths that bypass policy evaluation, enabling them to gain administrative privileges that the guardrail is designed to prevent.
Affected Systems
The affected product is the hulumi policies package (@hulumi/policies). Any deployment using versions earlier than 1.3.2 is susceptible. Applications that rely on this package for access control should verify their installed version and upgrade accordingly.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is high severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, but the nature of the flaw suggests that remote exploitation is possible if the attacker can submit or influence policy definitions. Once privilege escalation is achieved, the attacker can modify resources, access sensitive data, and disrupt services. Immediate remediation is strongly advised.
OpenCVE Enrichment