CVE-2026-92839: Canva
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Affected products
- Canva Canva: before 1.125.0 (fixed in 1.125.0)
Published 2026-09-17. Last modified 2026-09-18.