Impact
Canva Desktop versions prior to 1.125.0 performed double decoding of URLs in its deeplink handler. A crafted deeplink can resolve to arbitrary same‑origin content, causing the application to load that content under the active user session. This flaw, an Improper Encoding Handling issue (CWE-174), may expose sensitive data or alter the application state for the user.
Affected Systems
Canva Desktop for macOS and Windows, any version earlier than 1.125.0, is affected by the double‑decoding bug.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector involves delivering a malicious deeplink through social engineering or malicious content, with the primary impact being data exposure or manipulation within the application rather than remote code execution or privilege escalation.
OpenCVE Enrichment