bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: amazon-ssm-agent

show all
Friday, August 28, 2026

Critical Path Traversal in amazon-ssm-agent Requires Immediate Update

amazon-ssm-agent versions before 3.3.4515.0 have a path traversal vulnerability in the aws:downloadContent plugin that lets authenticated users write arbitrary files as root. This could lead to remote code execution if sensitive files get overwritten. Yes, you need to act: upgrade to 3.3.4515.0 or later ASAP if you're running affected versions (2.0.767.0 to 3.3.4364.0).

source: [aws/security-bulletin]