← Terug naar overzicht

A relative path traversal vulnerability exists in the zip extraction functionality of AWS diagram-as-code (awsdac) affecting versions 0.10 through 0.23. The flaw allows a third party to write arbitrary files to the local filesystem by crafting malicious zip entry names containing path traversal sequences. Exploitation could enable unauthorized file writes and inappropriate actions within the diagram bundle. The vulnerability is tracked as CVE-2026-81838 and was disclosed via NVD and an AWS security bulletin. Users are advised to upgrade to version 0.24 or later to remediate the issue. The fix is available on the official GitHub releases page for the awsdac project.

Affected products

  • AWS diagram-as-code (awsdac) 0.10 through 0.23

Related CVE's

  • CVE-2026-81838

Categories

  • Cloud & Virtualization
  • Supply Chain & Dependencies