bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Zip Slip

show all
Friday, August 28, 2026

awsdac Zip Slip Vulnerability Requires Immediate Update

awsdac (diagram-as-code) versions 0.10–0.23 have a critical Zip Slip path traversal flaw (CVE-2026-81838) that could let attackers execute arbitrary code when processing untrusted definition files. If you're running awsdac in CI/CD pipelines or handling definitions from external sources, update to version 0.24+ immediately and avoid the `--allow-untrusted-definitions` flag unless absolutely necessary. Local filesystem definitions bypass security checks, so be extra careful there.

source: [aws/security-bulletin]