CVE-2025-25977
EUVD-2025-626610.03.2025, 16:15
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canvg | canvg | 𝑥 < 3.0.11 |
| canvg | canvg | 4.0.0 ≤ 𝑥 < 4.0.3 |
𝑥
= Vulnerable software versions