CVE-2026-81838 MEDIUM

CVE-2026-81838: Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)

Vendor Aws
Product diagram-as-code
Weakness CWE-23
Published August 27, 2026
Last update August 28, 2026

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should upgrade to the version 0.24 or later.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated

Related vulnerabilities

04Related CVE