GHSA-v2mw-5mch-w8c5

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2mw-5mch-w8c5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-v2mw-5mch-w8c5/GHSA-v2mw-5mch-w8c5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v2mw-5mch-w8c5
Aliases
Related
Published
2025-03-10T18:31:56Z
Modified
2025-03-17T15:41:44Z
Severity
  • 8.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
canvg Prototype Pollution vulnerability
Details

An issue in canvg prior to v.4.0.3 and v3.0.11 can lead to prototype pollution via the Constructor of the class StyleElement.

Database specific
{
    "nvd_published_at": "2025-03-10T16:15:13Z",
    "cwe_ids": [
        "CWE-1321"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-12T15:33:44Z"
}
References

Affected packages

npm / canvg

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.0.3

npm / canvg

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.11