HIGH
GHSA-v2mw-5mch-w8c5
canvg Prototype Pollution vulnerability
Quick fix
GHSA-v2mw-5mch-w8c5 — canvg: upgrade to the fixed version with the command below.
npm install canvg@4.0.3Details
An issue in canvg prior to v.4.0.3 and v3.0.11 can lead to prototype pollution via the Constructor of the class StyleElement.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-25977[ADVISORY]
- https://github.com/canvg/canvg/issues/1749[WEB]
- https://github.com/canvg/canvg/commit/c3743e6345f3e01aefdcdd412c3f26494f4b5d7d[WEB]
- https://github.com/canvg/canvg[PACKAGE]
- https://github.com/canvg/canvg/blob/937668eced93e0335c67a255d0d2277ea708b2cb/src/Document/StyleElement.ts[WEB]