CVE-2026-48446

Source
https://cve.org/CVERecord?id=CVE-2026-48446
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48446.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48446
Published
2026-08-11T16:59:55Z
Modified
2026-09-09T11:45:20Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Details

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Database specific
{
    "cna_assigner": "adobe",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48446.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "c2pa-v0.90.5"
                },
                {
                    "last_affected": "c2patool-v0.27.5"
                },
                {
                    "last_affected": "@contentauth/c2pa-web@0.12.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/contentauth/c2patool

Affected ranges

Type
GIT
Repo
https://github.com/contentauth/c2patool
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:adobe:c2patool:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.27.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v0.*
v0.0.1
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.13.1
v0.13.3
v0.14.0
v0.15.0
v0.16.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.16.5
v0.17.0
v0.18.0
v0.19.0
v0.19.1
v0.2.0
v0.2.1
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.21.0
v0.22.0
v0.22.1
v0.23.0
v0.23.1
v0.23.2
v0.23.3
v0.23.4
v0.24.0
v0.25.0
v0.26.0
v0.26.1
v0.26.10
v0.26.11
v0.26.12
v0.26.13
v0.26.14
v0.26.15
v0.26.16
v0.26.17
v0.26.18
v0.26.19
v0.26.2
v0.26.20
v0.26.21
v0.26.24
v0.26.25
v0.26.26
v0.26.27
v0.26.29
v0.26.3
v0.26.30
v0.26.31
v0.26.32
v0.26.33
v0.26.34
v0.26.35
v0.26.36
v0.26.37
v0.26.38
v0.26.39
v0.26.4
v0.26.40
v0.26.41
v0.26.42
v0.26.43
v0.26.44
v0.26.45
v0.26.46
v0.26.47
v0.26.48
v0.26.49
v0.26.5
v0.26.50
v0.26.51
v0.26.52
v0.26.53
v0.26.54
v0.26.55
v0.26.56
v0.26.57
v0.26.58
v0.26.59
v0.26.6
v0.26.60
v0.26.61
v0.26.62
v0.26.63
v0.26.64
v0.26.65
v0.26.66
v0.26.67
v0.26.68
v0.26.69
v0.26.7
v0.26.70
v0.26.71
v0.26.72
v0.26.8
v0.26.9
v0.27.0
v0.27.0-rc.2
v0.27.0-rc.3
v0.27.1
v0.27.2
v0.27.3
v0.27.4
v0.27.5
v0.3.0
v0.3.1
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48446.json"