Description
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Published: 2026-03-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the EMF (Enhanced Metafile) processing of Canva Affinity. When the application parses a maliciously crafted EMF file, it accesses memory outside the intended buffer, which can expose secrets such as passwords, in‑process data, or other sensitive information that resides adjacent in memory. The weakness corresponds to CWE‑125, indicating a flaw in bounds checking that compromises data confidentiality.

Affected Systems

The affected product is Canva Affinity, identified by the vendor Affinity. The product’s CPE is cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*. No specific version information was disclosed; therefore, any running instance of this application is potentially vulnerable until a vendor‑issued fix is applied.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity. EPSS is below 1%, suggesting limited likelihood of widespread exploitation, and it is not listed in the CISA KEV catalog. The primary attack vector is local: a user must open the crafted EMF file with the application, so the risk is confined to environments where the file is processed by an authenticated or local user. Nonetheless, preventing exposure of sensitive data remains the key concern.

Generated by OpenCVE AI on March 19, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Canva Affinity vendor website for security patches or updates (e.g., https://trust.canva.com/).
  • Apply any available patch or upgrade instruction from the vendor.
  • If no patch is available, limit use of the EMF import feature and apply stricter file‑level permissions or disallow untrusted EMF files.
  • Validate incoming EMF files or use a sandboxed environment to open them.
  • Monitor for future updates by following the vendor’s advisories or subscribing to security bulletins.

Generated by OpenCVE AI on March 19, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Canva Affinity EMF Handling

Thu, 19 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

Wed, 18 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:canva:affinity:-:*:*:*:*:windows:*:*

Tue, 17 Mar 2026 21:30:00 +0000


Tue, 17 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Canva
Canva affinity
CPEs cpe:2.3:a:canva:affinity:-:*:*:*:*:windows:*:*
Vendors & Products Canva
Canva affinity
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2026-03-18T17:00:09.987Z

Reserved: 2025-12-05T12:14:58.187Z

Link: CVE-2025-62500

cve-icon Vulnrichment

Updated: 2026-03-17T20:11:25.312Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-17T19:15:58.423

Modified: 2026-03-19T12:24:04.270

Link: CVE-2025-62500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:54:49Z

Weaknesses