CVE-2025-66617: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66617?
CVE-2025-66617 has been rated as a moderate severity vulnerability due to its potential to disclose sensitive information.
How do I fix CVE-2025-66617?
To fix CVE-2025-66617, update Canva Affinity to version 3.1.0 or later.
What type of vulnerability is CVE-2025-66617?
CVE-2025-66617 is an out-of-bounds read vulnerability found in the EMF functionality of Canva Affinity.
Which software versions are affected by CVE-2025-66617?
CVE-2025-66617 affects all versions of Canva Affinity prior to 3.1.0.
What could an attacker achieve by exploiting CVE-2025-66617?
An attacker could exploit CVE-2025-66617 to perform an out-of-bounds read and potentially disclose sensitive information.