Path Traversal Vulnerability in AWS Diagram-as-Code by AWS
CVE-2026-81838

6.8MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81838?

The AWS Diagram-as-Code tool contains a vulnerability within its zip extraction feature, which can be exploited through crafted zip entry names that include path traversal sequences. This flaw enables unauthorized individuals to write arbitrary files to the local filesystem, potentially compromising the integrity of the diagram bundle and allowing unauthorized actions. Users are advised to upgrade to version 0.24 or later to address this issue effectively.

Affected Version(s)

diagram-as-code 0.10 <= 0.23

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.