CVE-2026-92839

Published: Set 17, 2026 Last Modified: Set 18, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,3
Source: 61adb53e-e4b3-47f7-8a93-4717c9e77dc6
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

174

Double Decoding of the Same Data

Draft
Common Consequences
Security Scopes Affected:
Access Control Confidentiality Availability Integrity Other
Potential Impacts:
Bypass Protection Mechanism Execute Unauthorized Code Or Commands Varies By Context
Applicable Platforms
All platforms may be affected
View CWE Details
https://trust.canva.com/?tcuUid=d98fa5aa-50ac-4e45-8fec-2c8d07f2b9b6