CVE-2026-81849: Path Traversal in SSM Agent's Download-Content Plugin
The aws:downloadContent plugin in amazon-ssm-agent improperly limits pathnames to a restricted directory. An authenticated remote user holding ssm:SendCommand permission scoped to the AWS-DownloadContent document can direct the agent to fetch a crafted S3 object whose key traverses outside the intended download directory, writing arbitrary files with root privileges - potentially leading to code execution if sensitive system files are overwritten. Affects SSM Agent 2.0.767.0 through 3.3.4364.0; fixed in 3.3.4515.0.
- amazon-ssm-agent 2.0.767.0-3.3.4364.0
- amazon-ssm-agent 3.3.4515.0