Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity of digital content and images, is affected by a security flaw that could allow an attacker to execute unauthorized code. By tricking a user into visiting a malicious link or interacting with a compromised web page, an attacker could gain control over the user's session or account. This could lead to the theft of sensitive information or the unauthorized modification of digital assets.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Adobe Content Authenticity (CAI) SDKs and command-line tools. The flaw allows an attacker to bypass security boundaries and potentially achieve arbitrary code execution or script injection by manipulating how the application handles external requests. Exploitation requires a local user to interact with a maliciously crafted URL or a compromised web page. The vulnerability affects the Rust SDK, JavaScript SDK, and the C2PA command-line tool, with patches available in newer versions (e.g., Rust SDK v0.85.2).
Affected products
- Adobe Content Credentials Rust SDK <= c2pa-v0.84.0
- Adobe Content Credentials Command-Line Tool <= c2patool-v0.16.5
- Adobe Content Credentials JS SDK <= @contentauth/c2pa-v0.16.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory