NPM · AUGUST 2026 · EARLY WARNING

Critical Vulnerability in @hulumi/drift npm Package: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
@hulumi/drift (npm)
Affected versions
< 1.3.2 or < 1.4.0
Patched version
1.3.2
CVE-2026-82858

An early warning has been issued for a critical vulnerability in the @hulumi/drift npm package versions before 1.3.2. This vulnerability allows attackers to supply malicious plans that bypass security checks.

What happened

The @hulumi/drift npm package versions before 1.3.2 reportedly accept externally supplied execute plans without sufficient provenance validation. This can allow attackers to supply malicious plans that bypass security checks, leading to unsafe reconciliation operations. The vulnerability is tracked as CVE-2026-82858 with a CVSS score of 9.8, indicating a critical severity. The issue was first flagged on 2026-08-31T09:17:06.067000+00:00.

To assess your exposure, check if your project is using @hulumi/drift npm package versions before 1.3.2 or before 1.4.0. If so, you are potentially affected by this vulnerability. It is recommended to upgrade to version 1.3.2 or later to mitigate the risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If @hulumi/drift is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if your project is using @hulumi/drift npm package versions before 1.3.2 or before 1.4.0.

What should I do right now?

Upgrade to @hulumi/drift version 1.3.2 or later to mitigate the vulnerability.

Is there an official fix available?

Yes, the patched version is 1.3.2 or later.

Where can I find more information about this vulnerability?

Consult the primary sources provided for more detailed information.

Sources

Join the 0Day waitlist →

← Back to all threats