Canva 旗下的 Affinity 应用在 3.3.0 版本之前(2026 年 9 月发布版本)在解析 Affinity 文档文件时未进行充分的边界检查,从而导致基于栈的缓冲区溢出漏洞。攻击者可以构造一个恶意的 Affinity 文档,当用户在 Affinity 中打开该文档时,可能导致任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet