Executive brief
Adobe Content Credentials tools, which are used to verify the authenticity and origin of digital media, are affected by a security flaw that could allow unauthorized access to local files. If a user is tricked into opening a specially crafted malicious file using these tools, an attacker could read sensitive information from the user's computer. This could lead to the exposure of private data or system configuration files.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity (CAI) SDKs and command-line tools. The flaw allows for an arbitrary file system read when the application processes a maliciously crafted file. The attack vector is local and requires user interaction, specifically that a victim opens the malicious file using an affected version of the Rust SDK, JS SDK, or the c2patool. Successful exploitation allows an attacker to read sensitive files and directories outside the intended scope of the application. Adobe has released updates to address this issue in Rust SDK v0.85.2, CLI tool v0.26.65, and JS SDK v0.16.6.
Affected products
- Adobe Content Credentials Rust SDK (c2pa) <= c2pa-v0.84.0
- Adobe Content Credentials Command-Line Tool (c2patool) <= c2patool-v0.16.5
- Adobe Content Credentials JS SDK (@contentauth/c2pa-js) <= 0.16.5
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory