Double Decoding Vulnerability in Canva Desktop by Canva
CVE-2026-92839
4.3MEDIUM
What is CVE-2026-92839?
Canva Desktop versions prior to 1.125.0 are susceptible to a double decoding vulnerability in the deeplink handler. This weakness allows malicious actors to exploit the application, potentially leading to the loading of arbitrary same-origin content under the user's session. Such behavior may compromise user data and session integrity, posing a significant threat to user security.
Affected Version(s)
Canva Windows 0 < 1.125.0
