Impact
The CAI Content Credentials components contain an Improper Input Validation flaw identified as CWE‑20 that allows an attacker to craft malicious input and cause the application to crash. The resulting crash ends the service, leading to a denial‑of‑service condition that cannot be recovered without application restart.
Affected Systems
Adobe’s Content Credentials Command‑Line Tool, the JavaScript SDK, and the Rust SDK are impacted. The advisory does not list affected versions, so any deployment of these components may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 marks this vulnerability as high severity. An EPSS score of < 1 % indicates that exploitation is considered unlikely, but it is still possible. No active exploits are listed in the KEV catalog. The vulnerability does not require user interaction, making it potentially exploitable remotely by sending crafted input to the affected components.
OpenCVE Enrichment