Skip to content

Deployment SCP template allowed hulumi:iac-role tag-on-create bypass

High
kerberosmansour published GHSA-86q4-r5j3-ff5c May 15, 2026

Software

kerberosmansour/hulumi deployment SCP template

Affected versions

< v1.3.2

Patched versions

v1.3.2

Description

Impact: repository revisions before v1.3.2 included a deployment SCP template that could allow tag-on-create bypasses for hulumi:iac-role protections, weakening the intended IAM boundary in downstream deployments.

Patched in v1.3.2: the SCP template and guide were tightened and covered by regression checks.

Remediation: update deployment templates and guidance from repository tag v1.3.2 or later.

Severity

High

CVE ID

No known CVE

Weaknesses

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. Learn more on MITRE.