CVE-2026-92839
MEDIUM
4,3
Source: 61adb53e-e4b3-47f7-8a93-4717c9e77dc6
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
Description
AI Translation Available
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
174
Double Decoding of the Same Data
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Availability
Integrity
Other
Potential Impacts:
Bypass Protection Mechanism
Execute Unauthorized Code Or Commands
Varies By Context
Applicable Platforms
All platforms may be affected
https://trust.canva.com/?tcuUid=d98fa5aa-50ac-4e45-8fec-2c8d07f2b9b6