A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2297 | Third Party Advisory Exploit |
| https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 | Vendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2297 | Third Party Advisory Exploit |
Configurations
History
No history.
Information
Published : 2026-03-17 19:15
Updated : 2026-03-19 12:11
NVD link : CVE-2025-66342
Mitre link : CVE-2025-66342
CVE.ORG link : CVE-2025-66342
JSON object : View
Products Affected
canva
- affinity
CWE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
