CVE-2025-25977

EUVD-2025-6266
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.59%
Affected Products (NVD)
VendorProductVersion
canvgcanvg
𝑥
< 3.0.11
canvgcanvg
4.0.0 ≤
𝑥
< 4.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
znuny
bookworm/non-free
vulnerable
forky/non-free
vulnerable
sid/non-free
6.5.24-1
fixed
trixie
no-dsa
trixie/non-free
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
znuny
jammy
dne
noble
needs-triage
resolute
needs-triage
otrs2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage