Description
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Canva Desktop versions prior to 1.125.0 performed double decoding of URLs in its deeplink handler. A crafted deeplink can resolve to arbitrary same‑origin content, causing the application to load that content under the active user session. This flaw, an Improper Encoding Handling issue (CWE-174), may expose sensitive data or alter the application state for the user.

Affected Systems

Canva Desktop for macOS and Windows, any version earlier than 1.125.0, is affected by the double‑decoding bug.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector involves delivering a malicious deeplink through social engineering or malicious content, with the primary impact being data exposure or manipulation within the application rather than remote code execution or privilege escalation.

Generated by OpenCVE AI on September 18, 2026 at 00:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Canva Desktop to version 1.125.0 or later.
  • Disable deeplink handling or block unknown link schemes if the application allows configuration of URL handlers.
  • Avoid clicking on unsolicited or suspicious deeplinks from untrusted sources.

Generated by OpenCVE AI on September 18, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Canva Desktop Double Decoding Enables Same‑Origin Content Loading

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
First Time appeared Canva
Canva canva
Weaknesses CWE-174
CPEs cpe:2.3:a:canva:canva:*:*:macos:*:*:*:*:*
cpe:2.3:a:canva:canva:*:*:windows:*:*:*:*:*
Vendors & Products Canva
Canva canva
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Canva

Published:

Updated: 2026-09-17T12:59:01.029Z

Reserved: 2026-09-17T01:04:32.559Z

Link: CVE-2026-92839

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:56.251Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T04:18:10.870

Modified: 2026-09-18T17:49:08.457

Link: CVE-2026-92839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-174

    Double Decoding of the Same Data