Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
https://trust.canva.com/?tcuUid=d98fa5aa-50ac-4e45-8fec-2c8d07f2b9b6