diff --git a/advisories/github-reviewed/2025/03/GHSA-v2mw-5mch-w8c5/GHSA-v2mw-5mch-w8c5.json b/advisories/github-reviewed/2025/03/GHSA-v2mw-5mch-w8c5/GHSA-v2mw-5mch-w8c5.json index 60a138b2f59..686757a3ed0 100644 --- a/advisories/github-reviewed/2025/03/GHSA-v2mw-5mch-w8c5/GHSA-v2mw-5mch-w8c5.json +++ b/advisories/github-reviewed/2025/03/GHSA-v2mw-5mch-w8c5/GHSA-v2mw-5mch-w8c5.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-v2mw-5mch-w8c5", - "modified": "2025-03-13T14:09:30Z", + "modified": "2025-03-17T15:41:44Z", "published": "2025-03-10T18:31:56Z", "aliases": [ "CVE-2025-25977" ], "summary": "canvg Prototype Pollution vulnerability", - "details": "An issue in canvg v.4.0.2 can lead to prototype pollution via the Constructor of the class StyleElement.", + "details": "An issue in canvg prior to v.4.0.3 and v3.0.11 can lead to prototype pollution via the Constructor of the class StyleElement.", "severity": [ { "type": "CVSS_V4", @@ -25,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "4.0.0" }, { "fixed": "4.0.3" @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "npm", + "name": "canvg" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.11" + } + ] + } + ] } ], "references": [