CVE-2025-25977 | canvg 4.0.2 StyleElement prototype pollution (Issue 1749 / EUVD-2025-6266)
A vulnerability, which was classified as critical, has been found in canvg 4.0.2. Affected by this issue is the function StyleElement. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is handled as CVE-2025-25977. The attack can only be done within the local network. There is no exploit available.