Critical Vulnerability in @hulumi/drift npm Package: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- @hulumi/drift (npm)
- Affected versions
- < 1.3.2 or < 1.4.0
- Patched version
- 1.3.2
An early warning has been issued for a critical vulnerability in the @hulumi/drift npm package versions before 1.3.2. This vulnerability allows attackers to supply malicious plans that bypass security checks.
What happened
The @hulumi/drift npm package versions before 1.3.2 reportedly accept externally supplied execute plans without sufficient provenance validation. This can allow attackers to supply malicious plans that bypass security checks, leading to unsafe reconciliation operations. The vulnerability is tracked as CVE-2026-82858 with a CVSS score of 9.8, indicating a critical severity. The issue was first flagged on 2026-08-31T09:17:06.067000+00:00.
To assess your exposure, check if your project is using @hulumi/drift npm package versions before 1.3.2 or before 1.4.0. If so, you are potentially affected by this vulnerability. It is recommended to upgrade to version 1.3.2 or later to mitigate the risk.
What to do about it
- Identify all instances of @hulumi/drift npm package in your project.
- Check the version of @hulumi/drift npm package being used.
- Upgrade to @hulumi/drift version 1.3.2 or later to mitigate the vulnerability.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
How 0Day would have caught this
@hulumi/drift is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if your project is using @hulumi/drift npm package versions before 1.3.2 or before 1.4.0.
What should I do right now?
Upgrade to @hulumi/drift version 1.3.2 or later to mitigate the vulnerability.
Is there an official fix available?
Yes, the patched version is 1.3.2 or later.
Where can I find more information about this vulnerability?
Consult the primary sources provided for more detailed information.