CVE-2026-92839: Canva

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

Affected products

  • Canva Canva: before 1.125.0 (fixed in 1.125.0)

Published 2026-09-17. Last modified 2026-09-18.