PT-2026-48281 · C2Pa-V+1 · C2Pa-V+1

CVE-2026-34657

·

Published

2026-06-09

·

Updated

2026-08-26

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions c2pa-web versions prior to 0.7.1 c2pa-v versions prior to 0.80.1
Description An improper limitation of a pathname to a restricted directory, known as Path Traversal, allows for an arbitrary file system write. This issue enables an attacker to write to unauthorized files or directories outside of intended restrictions. Exploitation requires user interaction, specifically that a victim extracts a maliciously crafted file.
Recommendations Update c2pa-web to version 0.7.1 or later. Update c2pa-v to version 0.80.1 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08499
CVE-2026-34657

Affected Products

C2Pa-V
C2Pa-Web