Canvg is a lightweight SVG-to-Canvas rendering library used to enable vector graphics display in environments with limited Canvas support. The vendor's vulnerability profile centers on prototype-pollution weaknesses in the core library, reflecting the risks inherent to JavaScript object-manipulation logic in parsing and rendering operations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Canvg over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25977CRITICAL An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement. | Mar 10, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Canvg.
Media articles that mention a CVE ID that affects a product developed by Canvg — matched by CVE ID, not by vendor name.