Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rhgj-6g2c-frmm | @hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name |
Fri, 24 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0. | |
| Title | Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-24T19:16:19.349Z
Reserved: 2026-05-20T18:15:53.577Z
Link: CVE-2026-48033
Updated: 2026-07-24T19:16:15.347Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA