Impact
The vulnerability is an improper input validation flaw that allows an attacker to read arbitrary files on the file system. An attacker can access sensitive files and directories outside the intended scope if a user opens a malicious file. The weakness is CWE‑20, and the primary impact is the potential exposure of confidential data, resulting in a confidentiality compromise.
Affected Systems
Adobe offers the Content Credentials Command‑Line Tool, JavaScript SDK, and Rust SDK. Any affected version of these products is vulnerable; vendors have not provided specific version ranges in the advisory.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate severity, while the EPSS score is below 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require user interaction: a victim must open a malicious file, making the vector social‑engineering or local file compromise rather than remote exploitation. Overall, the risk is moderate but the exploitation probability remains low.
OpenCVE Enrichment