CVE-2026-92839
EUVD-2026-8131717.09.2026, 04:18
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canva | canva | 𝑥 < 1.125.0 | CNA |
Common Weakness Enumeration