Impact
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By supplying a specially crafted EMF file, an attacker can trigger the application to read beyond the boundaries of a buffer, potentially exposing confidential data. The weakness is mapped to CWE-125, which denotes an array index error leading to memory corruption.
Affected Systems
The vulnerability affects Canva Affinity running on Windows platforms. The CPE data (cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*) indicates the product but does not specify individual versions, meaning that all current releases of Canva Affinity on Windows could be impacted unless a vendor patch has already addressed the flaw.
Risk and Exploitability
The CVSS base score of 6.1 places this issue in the moderate severity range. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a malicious EMF file to be opened by the target, implying a local or user‑initiated attack vector; no remote network entry point is defined in the description.
OpenCVE Enrichment