Path Traversal Vulnerability in AWS Diagram-as-Code by AWS
CVE-2026-81838
6.8MEDIUM
What is CVE-2026-81838?
The AWS Diagram-as-Code tool contains a vulnerability within its zip extraction feature, which can be exploited through crafted zip entry names that include path traversal sequences. This flaw enables unauthorized individuals to write arbitrary files to the local filesystem, potentially compromising the integrity of the diagram bundle and allowing unauthorized actions. Users are advised to upgrade to version 0.24 or later to address this issue effectively.
Affected Version(s)
diagram-as-code 0.10 <= 0.23
