Canva · Canva Desktop · CVE-2026-92839
**Name of the Vulnerable Software and Affected Versions**
Canva Desktop versions prior to 1.125.0
**Description**
The application performs double decoding within the deeplink handler. This behavior allows a threat actor to force the application to load arbitrary same-origin content using the active user session.
**Recommendations**
Update Canva Desktop to version 1.125.0 or later.