CVE-2026-92839
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 17, 2026
Vendor
unknown
Description
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.