Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-82862 is an arbitrary code execution vulnerability in Hulumi versions before v1.3.2 that stems from unsafe resolution of a threat-model helper script from the root directory. The vulnerability allows attackers to shadow the legitimate helper script with malicious files placed in the workspace, which are then executed with the privileges of the user running local skill execution. This affects security practitioners and development teams using Hulumi for threat modeling, particularly in environments where workspace directories may be shared or where an attacker has write access to project folders. The high CVSS score of 8.4 reflects the severity of arbitrary code execution in a local context.
While this CVE does not currently map to specific MITRE ATT&CK techniques, Casky's security skills would detect attack patterns associated with CWE-426 (Untrusted Search Path) by analyzing file resolution behaviors and execution contexts. Practitioners using Casky's extended reasoning capabilities would observe findings related to suspicious file shadowing, unexpected script sources, and execution chains originating from workspace-controlled paths rather than system or verified directories. Detection would focus on identifying when helper scripts are resolved from user-writable locations, analyzing execution context mismatches, and correlating file modifications in workspaces with subsequent process execution—revealing the classic supply-chain-like attack pattern where workspace pollution leads to code execution during routine security skill operations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82862. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation