CVE-2025-66342: Canva Affinity

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.

Affected products

  • Canva Affinity: before 3.1.0 (fixed in 3.1.0)

Published 2026-03-17. Last modified 2026-06-17.