Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 3.0.1.3808
affected
Description
An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.
Problem types
Product status
Credits
Discovered by KPC of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2310
talosintelligence.com/vulnerability_reports/TALOS-2025-2310
trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62