PT-2026-48281 · C2Pa-V+1 · C2Pa-V+1
CVE-2026-34657
·
Published
2026-06-09
·
Updated
2026-08-26
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
c2pa-web versions prior to 0.7.1
c2pa-v versions prior to 0.80.1
Description
An improper limitation of a pathname to a restricted directory, known as Path Traversal, allows for an arbitrary file system write. This issue enables an attacker to write to unauthorized files or directories outside of intended restrictions. Exploitation requires user interaction, specifically that a victim extracts a maliciously crafted file.
Recommendations
Update c2pa-web to version 0.7.1 or later.
Update c2pa-v to version 0.80.1 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
C2Pa-V
C2Pa-Web