Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h597-3g4m-44qj

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.

EPSS

Процентиль: 16%
0.00242
Низкий

7.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 месяца назад

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 7.1
fstec
около 1 месяца назад

Уязвимость наборов библиотек Content Credentials SDK, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записывать произвольные файлы

EPSS

Процентиль: 16%
0.00242
Низкий

7.1 High

CVSS3

Дефекты

CWE-22