Impact
Affinity by Canva, a document editing application, has a stack-based buffer overflow in its document parser. The application fails to enforce bounds checking when handling Affinity document files, allowing an attacker to craft a malicious file that, when opened by a user, can execute arbitrary code on the victim’s machine.
Affected Systems
The vulnerability exists in all versions of Affinity prior to 3.3.0 released in September 2026. Users running the affected Canva Affinity application on any operating system that supports the program are at risk if they open malicious documents.
Risk and Exploitability
The CVSS score of 7.7 indicates a high impact, while the EPSS score of less than 1% suggests a currently low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply a crafted Affinity file to the victim, typically through social engineering or malicious email attachments. Successful exploitation grants arbitrary code execution within the context of the document viewer process.
OpenCVE Enrichment