Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file writt...

This version

Version
1 of 3
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
45c7b23a373ca7e023b847edf5452f11
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.