Impact
The vulnerability allows a malicious file placed in the workspace to override the intended threat‑model helper script. During local skill execution, the system will load and run the attacker‑controlled helper, enabling arbitrary code execution within the user’s environment. This flaw directly exposes the integrity and confidentiality of data and can lead to full compromise of the host if the attacker has write access to the workspace.
Affected Systems
The affected system is Hulumi by kerberosmansour. Versions prior to 1.3.2 are impacted. Users installing any pre‑1.3.2 release should verify the version and upgrade to 1.3.2 or later to eliminate the flaw.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, but the vulnerability is listed as not part of the CISA KEV catalog. Attackers with write permission to a workspace can achieve arbitrary code execution simply by placing a malicious file, making exploitation straightforward without additional prerequisites.
OpenCVE Enrichment