CVE-2026-34657: CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
c2pa-webfrom your environment.If these components are present and cannot be updated to a fixed release, uninstall c2pa-web (and any associated c2pa tooling) until a vendor-provided fix is available.
- Remove
Remove
c2pa-vfrom your environment.If these components are present and cannot be updated to a fixed release, uninstall c2pa-v (and any associated c2pa tooling) until a vendor-provided fix is available.
- Compensating control
Prevent exploitation by restricting user activity that can trigger the vulnerability: do not open or extract files from untrusted or unknown sources; block or filter potentially malicious archive/file types at email gateways or endpoint protection; scan files with up-to-date antivirus/antimalware before extraction.
- Operational
If file extraction from untrusted sources occurred, inspect hosts for unauthorized filesystem writes, restore affected files from known-good backups, and investigate to determine if the vulnerability was exploited.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34657?
CVE-2026-34657 has a medium severity score of 5.5.
What systems are affected by CVE-2026-34657?
CVE-2026-34657 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
How do I fix CVE-2026-34657?
To fix CVE-2026-34657, update the affected CAI Content Credentials software to the latest versions.
What type of vulnerability is CVE-2026-34657?
CVE-2026-34657 is classified as an Improper Limitation of a Pathname to a Restricted Directory, commonly referred to as a Path Traversal vulnerability.
What could an attacker exploit in CVE-2026-34657?
An attacker could exploit CVE-2026-34657 to perform an arbitrary file system write.