CVE-2025-25977

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
References
Link Resource
https://github.com/canvg/canvg/issues/1749 Exploit Issue Tracking
https://github.com/canvg/canvg/issues/1749 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canvg:canvg:*:*:*:*:*:*:*:*
cpe:2.3:a:canvg:canvg:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-10 16:15

Updated : 2025-03-25 16:53


NVD link : CVE-2025-25977

Mitre link : CVE-2025-25977

CVE.ORG link : CVE-2025-25977


JSON object : View

Products Affected

canvg

  • canvg
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')