CVE-2025-25977
10.03.2025, 16:15
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
Vendor | Product | Version |
---|---|---|
canvg | canvg | 𝑥 < 3.0.11 |
canvg | canvg | 4.0.0 ≤ 𝑥 < 4.0.3 |
𝑥
= Vulnerable software versions