云虫漏洞情报

CVE-2026-81838 - A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should upgrade to the version 0.24 or later. - 漏洞详情

漏洞编号:CVE-2026-81838

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-81838

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-23

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle.



To remediate this issue, users should upgrade to the version 0.24 or later.

相关链接

相关漏洞

« 返回首页