Количество 3
Количество 3
CVE-2026-48442
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
GHSA-h597-3g4m-44qj
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
BDU:2026-11916
Уязвимость наборов библиотек Content Credentials SDK, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записывать произвольные файлы
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48442 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
GHSA-h597-3g4m-44qj CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
BDU:2026-11916 Уязвимость наборов библиотек Content Credentials SDK, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю записывать произвольные файлы | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу