highVulnerability

GHSA-2ffm-hxrq-qqmm

Impact: @hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted. Patched in 1.3.2: execute-plan handling now validates provenance and rejects untrusted plans, with regression coverage. Remediation: upgrade @hulumi/drift to 1.3.2 or later.

Properties

ghsa_id
GHSA-2ffm-hxrq-qqmm
summary
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
severity
high
cve_id
GHSA-2ffm-hxrq-qqmm
is_ghsa_only
true
ghsa_published
2026-05-21T20:43:41Z
source_url
https://github.com/advisories/GHSA-2ffm-hxrq-qqmm
ghsa_updated
2026-05-21T20:43:42Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@hulumi/drift

AFFECTS (1)

[Software]npm/@hulumi/drift

HAS_WEAKNESS (1)

[Weakness]Insufficient Verification of Data Authenticity

Explore deeper with Ninja Signal's threat intelligence graph