CVE-2025-66342

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

History

19 Mar 2026, 12:11

Type Values Removed Values Added
First Time Canva
Canva affinity
CPE cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2297 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2297 - Third Party Advisory, Exploit
References () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2297 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2297 - Third Party Advisory, Exploit

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de confusión de tipos existe en la funcionalidad EMF de Canva Affinity. Un archivo EMF especialmente diseñado puede desencadenar esta vulnerabilidad, lo que puede llevar a corrupción de memoria y resultar en ejecución de código arbitrario.

17 Mar 2026, 21:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2297 -

17 Mar 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 19:15

Updated : 2026-03-19 12:11


NVD link : CVE-2025-66342

Mitre link : CVE-2025-66342

CVE.ORG link : CVE-2025-66342


JSON object : View

Products Affected

canva

  • affinity
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')