Historical version

This is version 2, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

Amazon Web Services Version 2 imported change

Imported from official source

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the intended cache directory, to any path writable by the user running awsdac. Depending on the file written, this can lead to arbitrary code execution. Leveraging this issue requires processing a definition file from an untrusted source. This can occur when: - awsdac is run without definition trust restrictions (versions prior to 0.22.4 had no trust distinction; version 0.22.4 and later require the −−allow−untrusted−definitions flag), or - a definition file is loaded from the local filesystem ('Type: LocalFile'), which bypasses the definition URL allowlist. CI/CD environments that process definition files from untrusted or semi-trusted sources are the primary risk scenario. awsdac is a client-sid...

This version

Version
2 of 3
Recorded
September 17, 2026 21:30
Change
Imported change
Content hash
89c51f5c8df5485a18e5160f91b15dee
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.