CVE-2026-81838CWE-23

CVE-2026-81838

High · published August 28, 2026

CVSS v3.1
7.1
EPSS
0%
Percentile
3.2
In the wild
Unconfirmed
What it is

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle.

To remediate this issue, users should upgrade to the version 0.24 or later.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
CVSS v4.0
6.8 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00134 · 3.2th percentile
Weakness
CWE-23 · Relative Path Traversal
Published
2026-08-28T00:18Z
Affected products (1)
ProductVersionsFixed in
amazon/diagram-as-code≥ 0.10, < 0.240.24
References (2)
EPSS history
Timeline
  • 27 AUG 20:03Z
    Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)
    cvelistv5