{"id":"CVE-2026-92839","title":"Canva Desktop before v1.125.0 performed double decoding in the deeplink handler","summary":"Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-174"],"vendor":"Canva","product":"Canva","affected":["Canva < 1.125.0"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T17:49:08.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92839","references":[{"url":"https://trust.canva.com/?tcuUid=d98fa5aa-50ac-4e45-8fec-2c8d07f2b9b6","label":"61adb53e-e4b3-47f7-8a93-4717c9e77dc6"}],"tags":["nvd","cve.org"],"epss":0.00214,"epssPercentile":0.11989,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T12:57:36.832056Z"},"ingestedAt":"2026-09-17T04:10:55.620Z","slug":"CVE-2026-92839","body":"## Overview\n\nCanva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}