Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-25977

Опубликовано: 10 мар. 2025
Источник: redhat
CVSS3: 6.5

Описание

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

A flaw was found in the canvg library. In affected versions, an attacker can manipulate the input to the StyleElement constructor to inject or alter properties within the global prototype chain. This can lead to other injection-based attacks, particularly if the library is integrated into an application in a way that interacts with sensitive Node.js APIs, such as exec or eval.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1321
https://bugzilla.redhat.com/show_bug.cgi?id=2351128canvg: Prototype Pollution Vulneralbility

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
10 месяцев назад

An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.

github
10 месяцев назад

canvg Prototype Pollution vulnerability

CVSS3: 9.8
fstec
11 месяцев назад

Уязвимость класса StyleElement библиотеки обработки SVG-изображений canvg, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»

6.5 Medium

CVSS3