High severity7.1NVD Advisory· Published Aug 27, 2026
CVE-2026-81838
CVE-2026-81838
Description
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle.
To remediate this issue, users should upgrade to the version 0.24 or later.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.23
- Range: <=0.23
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.