Path traversal in Content Credentials JS SDK and Content Credentials Rust SDK - CVE-2026-34657

 

Path traversal in Content Credentials JS SDK and Content Credentials Rust SDK - CVE-2026-34657

Published: July 15, 2026


Vulnerability identifier: #VU137688
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34657
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform an arbitrary file system write.

The vulnerability exists due to path traversal in Content Credentials Rust SDK when handling crafted file paths. A remote attacker can trick the victim into opening crafted content to perform an arbitrary file system write.

User interaction is required to open crafted content.


Affected software

Content Credentials JS SDK
Content Credentials Rust SDK

How to mitigate CVE-2026-34657

Install security update from vendor's website.

Content Credentials JS SDK - update to 0.8.3
Content Credentials Rust SDK - update to 0.85.1

External References

Related Security Bulletins