CVE-2025-64301

An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

History

19 Mar 2026, 12:24

Type Values Removed Values Added
CPE cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*
First Time Canva
Canva affinity
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2310 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2310 - Exploit, Third Party Advisory
References () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2310 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2310 - Exploit, Third Party Advisory

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de escritura fuera de límites en la funcionalidad EMF de Canva Affinity. Al usar un archivo EMF especialmente diseñado, un atacante podría explotar esta vulnerabilidad para realizar una escritura fuera de límites, lo que podría llevar a la ejecución de código.

17 Mar 2026, 21:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2310 -

17 Mar 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 19:15

Updated : 2026-03-19 12:24


NVD link : CVE-2025-64301

Mitre link : CVE-2025-64301

CVE.ORG link : CVE-2025-64301


JSON object : View

Products Affected

canva

  • affinity
CWE
CWE-787

Out-of-bounds Write