CVE-2025-66342: Canva Affinity
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
Affected products
- Canva Affinity: before 3.1.0 (fixed in 3.1.0)
Published 2026-03-17. Last modified 2026-06-17.