CVE-2025-66000
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
- Affected products
- Affinity
- Canva Affinity
- < 3.1.0
- CVSS 3.1
- 7.1 HIGH
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-125
- NVD status
- Analyzed
- Published
- 2026-03-17
CVE-2025-66000 at NVD
No indexed exploits for CVE-2025-66000 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-66000 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.