<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hulumi:drift:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahulumidrift/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 11:16:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahulumidrift/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Provenance Validation in @hulumi/drift</title><link>https://feed.craftedsignal.io/briefs/2026-08-drift-vulnerability/</link><pubDate>Mon, 31 Aug 2026 11:16:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-drift-vulnerability/</guid><description>The @hulumi/drift package versions prior to 1.3.2 are susceptible to malicious reconciliation plan injection due to insufficient validation of externally supplied execute plans.</description><content:encoded><![CDATA[<p>The @hulumi/drift package, specifically in versions prior to 1.3.2, contains a critical security vulnerability (CVE-2026-82858) stemming from improper validation of execute plans. The application accepts reconciliation plans from external sources without verifying their origin or integrity. This flaw enables an attacker to supply a crafted, malicious execute plan that is treated as trusted by the system. If exploited, an attacker can bypass security controls intended to govern reconciliation operations, leading to the execution of unauthorized or unsafe system modifications. Given the nature of drift management tools, this could result in significant state manipulation or unauthorized infrastructure changes. Defenders should prioritize updating to version 1.3.2 or later to ensure that execute plans are subjected to proper validation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized actors to bypass security checks and force the execution of arbitrary or malicious reconciliation operations. This could lead to unauthorized state changes, potential data loss, or system instability within the managed infrastructure. The scope of impact is limited to environments utilizing the @hulumi/drift package for reconciliation, with the severity being classified as critical (CVSS 9.8).</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade @hulumi/drift to version 1.3.2 or later immediately to address the lack of provenance validation for execute plans.</li>
<li>Audit logs for reconciliation operations to identify anomalies in the execution plan source or content occurring prior to the patch.</li>
<li>Restrict access to systems capable of submitting external reconciliation plans to only verified and trusted service identities.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>