Security: kerberosmansour/hulumi
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Deployment SCP template allowed hulumi:iac-role tag-on-create bypassGHSA-86q4-r5j3-ff5c published
May 15, 2026 by kerberosmansourHigh -
CIS 1.16 admin policy bypass for inline and attached IAM policiesGHSA-4xrh-5m3m-328w published
May 15, 2026 by kerberosmansourHigh -
HULUMI-H1 SecureBucket parent spoof bypassGHSA-g43v-9x7q-83pq published
May 15, 2026 by kerberosmansourHigh -
Threat-model skill helper script root could be shadowed by workspace filesGHSA-mjcg-x5mr-27ww published
May 15, 2026 by kerberosmansourModerate -
CloudTrail selector tampering events were not fully detectedGHSA-gfp8-mp24-5vxg published
May 15, 2026 by kerberosmansourModerate