Vulnerability Details CVE-2026-4345
A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.5%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2026-4345
-
cpe:2.3:a:autodesk:fusion:2.0.20754
-
cpe:2.3:a:autodesk:fusion:2.0.20948
-
cpe:2.3:a:autodesk:fusion:2.0.20962
-
cpe:2.3:a:autodesk:fusion:2.0.20970
-
cpe:2.3:a:autodesk:fusion:2.0.20981
-
cpe:2.3:a:autodesk:fusion:2.0.21286
-
cpe:2.3:a:autodesk:fusion:2.0.21487
-
cpe:2.3:a:autodesk:fusion:2.0.21508
-
cpe:2.3:a:autodesk:fusion:2.0.21528
-
cpe:2.3:a:autodesk:fusion:2.0.21538
-
cpe:2.3:a:autodesk:fusion:2.0.21550
-
cpe:2.3:a:autodesk:fusion:2601.0.90
-
cpe:2.3:a:autodesk:fusion:2601.1.29
-
cpe:2.3:a:autodesk:fusion:2601.1.34
-
cpe:2.3:a:autodesk:fusion:2601.1.37
-
cpe:2.3:a:autodesk:fusion:2602.0.71
-
cpe:2.3:a:autodesk:fusion:2602.1.14
-
cpe:2.3:a:autodesk:fusion:2602.1.25
-
cpe:2.3:a:autodesk:fusion:2603.0.86
-
cpe:2.3:a:autodesk:fusion:2603.1.15
-
cpe:2.3:a:autodesk:fusion:2603.1.31
-
cpe:2.3:a:autodesk:fusion:2603.1.52
-
cpe:2.3:a:autodesk:fusion:2604.1.25
-
cpe:2.3:a:autodesk:fusion:2604.1.48
-
cpe:2.3:a:autodesk:fusion:2605.0.97
-
cpe:2.3:a:autodesk:fusion:2605.1.18
-
cpe:2.3:a:autodesk:fusion:2605.1.39
-
cpe:2.3:a:autodesk:fusion:2605.1.52
-
cpe:2.3:a:autodesk:fusion:2606.1.21
-
cpe:2.3:a:autodesk:fusion:2606.1.22