Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 18, 2026
CVE-2025-66342
CVE-2025-66342
Description
A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
2- Agents that remember: introducing Agent MemoryCloudflare Blog · Apr 17, 2026
- Building the foundation for running extra-large language modelsCloudflare Blog · Apr 16, 2026