GHSA-fq87-2rvp-5478HighCVSS 7.7

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.

🔗 References (3)