CVE-2026-34657: CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in an arbitrary file system write. An attacker could leverage this vulnerability to write to unauthorized files or directories outside of intended restrictions. Exploitation of this issue requires user interaction in that a victim must extract a maliciously crafted file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CAI Content Credentialsto a version that resolves this vulnerability.Fixed in c2pa-web@0.7.1 - Upgrade
Upgrade
CAI Content Credentialsto a version that resolves this vulnerability.Fixed in c2pa-v0.80.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34657?
CVE-2026-34657 has a medium severity score of 5.5.
What systems are affected by CVE-2026-34657?
CVE-2026-34657 affects CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier.
How do I fix CVE-2026-34657?
To fix CVE-2026-34657, update the affected CAI Content Credentials software to the latest versions.
What type of vulnerability is CVE-2026-34657?
CVE-2026-34657 is classified as an Improper Limitation of a Pathname to a Restricted Directory, commonly referred to as a Path Traversal vulnerability.
What could an attacker exploit in CVE-2026-34657?
An attacker could exploit CVE-2026-34657 to perform an arbitrary file system write.