Impact
CAI Content Credentials is affected by a path traversal flaw that lets an attacker read files outside the intended directory. The vulnerability occurs when a user processes a crafted pathname and can result in arbitrary file system reads, potentially exposing sensitive application or system files. The impact is strictly confidentiality loss; there is no evidence of code execution or privilege escalation in the supplied description.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are all affected. No specific version range is provided in the advisory, so any installation of these components may be vulnerable until updated.
Risk and Exploitability
The CVSS score of 5.5 places the issue in the moderate severity range. EPSS is listed as less than 1%, indicating a very low probability of exploitation as of now, and the vulnerability is not in the CISA KEV catalog. However, because exploitation requires a victim to visit a maliciously crafted URL or interact with a compromised web page, the risk is tied to user behavior. If users are exposed to phishing or compromised sites, the path traversal could be triggered. Mitigation of the flaw is essential to prevent possible confidential data exposure.
OpenCVE Enrichment