PT-2026-94134 · Canva · Affinity
CVSS v3.1
7.7
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Affinity by Canva versions prior to 3.3.0
Description
Insufficient bounds checking during the parsing of Affinity document files leads to a stack-based buffer overflow. This occurs when the application processes a specially crafted document, which can allow a threat actor to achieve arbitrary code execution on the system.
Recommendations
Update to version 3.3.0 or later.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Affinity