CVE-2025-25977

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
References
Link Resource
https://github.com/canvg/canvg/issues/1749 Exploit Issue Tracking
https://github.com/canvg/canvg/issues/1749 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canvg:canvg:*:*:*:*:*:*:*:*
cpe:2.3:a:canvg:canvg:*:*:*:*:*:*:*:*

History

25 Mar 2025, 16:53

Type Values Removed Values Added
First Time Canvg canvg
Canvg
CPE cpe:2.3:a:canvg:canvg:*:*:*:*:*:*:*:*
References () https://github.com/canvg/canvg/issues/1749 - () https://github.com/canvg/canvg/issues/1749 - Exploit, Issue Tracking

12 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/canvg/canvg/issues/1749 - () https://github.com/canvg/canvg/issues/1749 -
CWE CWE-1321
Summary
  • (es) Un problema en canvg v.4.0.2 permite a un atacante ejecutar código arbitrario a través del Constructor de la clase StyleElement.

10 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 16:15

Updated : 2025-03-25 16:53


NVD link : CVE-2025-25977

Mitre link : CVE-2025-25977

CVE.ORG link : CVE-2025-25977


JSON object : View

Products Affected

canvg

  • canvg
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')