@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-82856 exploits inadequate validation of AWS IAM condition operators in GitHub OIDC trust policies within the @hulumi/policies library. By leveraging ForAnyValue:StringLike operators, attackers can craft policies that circumvent security guardrails designed to restrict GitHub Actions OIDC subject conditions. This vulnerability affects any organization using @hulumi/policies versions before 1.3.2 to manage OIDC trust relationships—a critical control point for supply chain security. The attack succeeds because the library fails to recognize that set-qualified operators can mask overly permissive wildcard patterns, allowing unauthorized GitHub Actions workflows to assume AWS roles intended for specific, restricted subjects.
Casky's Claude-powered analysis detects the attack patterns underlying this vulnerability by examining policy validation logic across identity and access management controls. Practitioners would observe findings related to Technique T1110 (Brute Force) and T1078 (Valid Accounts) abuse patterns, where overly permissive OIDC conditions enable lateral movement or privilege escalation. Extended reasoning surfaces subtle condition operator combinations that evade simple string matching—specifically identifying where ForAnyValue operators combined with wildcards create logical contradictions with intended security policies. Security teams using Casky would see detailed explanations of why a policy fails validation, which operators are problematic, and how attackers exploit the gap between policy intent and library interpretation, enabling rapid remediation before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82856. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation