CVE-2025-64301: Canva Affinity
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.
Affected products
- Canva Affinity: before 3.1.0 (fixed in 3.1.0)
Published 2026-03-17. Last modified 2026-06-17.