CPE
The @hulumi/drift package versions prior to 1.3.2 are susceptible to malicious reconciliation plan injection due to insufficient validation of externally supplied execute plans.