CVE-2026-81838

Source
https://cve.org/CVERecord?id=CVE-2026-81838
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81838.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81838
Published
2026-08-27T20:03:59.258Z
Modified
2026-08-30T03:30:45.991157774Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)
Details

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle.

To remediate this issue, users should upgrade to the version 0.24 or later.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81838.json",
    "cwe_ids": [
        "CWE-23"
    ],
    "cna_assigner": "AMZN"
}
References

Affected packages

Git / github.com/awslabs/diagram-as-code

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/diagram-as-code
Events
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0.10"
        },
        {
            "fixed": "0.23"
        }
    ]
}

Affected versions

v0.*
v0.10
v0.12
v0.20
v0.21.0
v0.21.1
v0.21.10
v0.21.11
v0.21.12
v0.21.2
v0.21.3
v0.21.4
v0.21.5
v0.21.6
v0.21.7
v0.21.8
v0.21.9
v0.22
v0.22.1
v0.22.2
v0.22.3
v0.22.4
v0.23

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81838.json"