CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Cybersecurity Classified by Officially
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Bulletin ID: 2026-090-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/27/2026 13:00 PM PDT
Last Updated: 08/28/2026 09:30 AM PDT
awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file written, this can lead to arbitrary code execution.
Leveraging this issue requires processing a definition file from an untrusted source. This can occur when:
CI/CD environments that process definition files from untrusted or semi-trusted sources are the primary risk scenario.
awsdac is a client-side CLI tool that renders architecture diagrams locally. This issue does not affect any AWS service, AWS account, or customer data. The impact is limited to the machine on which awsdac runs.
Impacted versions: awsdac: versions 0.10 through 0.23 (inclusive)
This issue has been addressed in version 0.24. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-090-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
3 versions recorded. The original is kept in full — nothing is overwritten.
- v3 imported change on current
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 15, 2026 20:57
- Versions
- 3 recorded
- Identity
fc72305d6fa73928de5a5278d918b06c5ee71268