CVE-2026-48442

Source
https://cve.org/CVERecord?id=CVE-2026-48442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48442
Published
2026-08-11T16:59:59Z
Modified
2026-09-09T11:45:16Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Details

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.

Database specific
{
    "cna_assigner": "adobe",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48442.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "c2pa-v0.90.5"
                },
                {
                    "last_affected": "c2patool-v0.27.5"
                },
                {
                    "last_affected": "@contentauth/c2pa-web@0.12.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/contentauth/c2patool

Affected ranges

Type
GIT
Repo
https://github.com/contentauth/c2patool
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.27.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v0.*
v0.0.1
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.13.1
v0.13.3
v0.14.0
v0.15.0
v0.16.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.16.5
v0.17.0
v0.18.0
v0.19.0
v0.19.1
v0.2.0
v0.2.1
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.21.0
v0.22.0
v0.22.1
v0.23.0
v0.23.1
v0.23.2
v0.23.3
v0.23.4
v0.24.0
v0.25.0
v0.26.0
v0.26.1
v0.26.10
v0.26.11
v0.26.12
v0.26.13
v0.26.14
v0.26.15
v0.26.16
v0.26.17
v0.26.18
v0.26.19
v0.26.2
v0.26.20
v0.26.21
v0.26.24
v0.26.25
v0.26.26
v0.26.27
v0.26.29
v0.26.3
v0.26.30
v0.26.31
v0.26.32
v0.26.33
v0.26.34
v0.26.35
v0.26.36
v0.26.37
v0.26.38
v0.26.39
v0.26.4
v0.26.40
v0.26.41
v0.26.42
v0.26.43
v0.26.44
v0.26.45
v0.26.46
v0.26.47
v0.26.48
v0.26.49
v0.26.5
v0.26.50
v0.26.51
v0.26.52
v0.26.53
v0.26.54
v0.26.55
v0.26.56
v0.26.57
v0.26.58
v0.26.59
v0.26.6
v0.26.60
v0.26.61
v0.26.62
v0.26.63
v0.26.64
v0.26.65
v0.26.66
v0.26.67
v0.26.68
v0.26.69
v0.26.7
v0.26.70
v0.26.71
v0.26.72
v0.26.8
v0.26.9
v0.27.0
v0.27.0-rc.2
v0.27.0-rc.3
v0.27.1
v0.27.2
v0.27.3
v0.27.4
v0.27.5
v0.3.0
v0.3.1
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48442.json"