Description

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.

Severity (CVSS)

Base score6.8
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Provided byCNA

Weaknesses

  • CWE-20 — Improper Input Validation (CWE-20)

Affected products

VendorProductVersions
AdobeContent Credentials Rust SDK0 to <=c2pa-v0.84.0; c2pa-v0.85.2
AdobeContent Credentials Command-Line Tool0 to <=c2patool-v0.16.5; c2patool-v0.26.65
AdobeContent Credentials JS SDK0 to <=@contentauth/c2pa-web@0.7.0; @contentauth/c2pa-web@0.9.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.