CVE-2026-0535
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0535 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A maliciously crafted HTML payload embedded in a component's description field can be triggered when a user clicks on it, potentially allowing an attacker to read local files or execute arbitrary code within the context of the running process. All Autodesk Fusion versions prior to 2606.1.21 are affected. The CVE was published on January 22, 2026, with a patch released by January 30, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Autodesk (Autodesk Advisory, NVD).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored/persistent variant (NVD). The root cause is insufficient sanitization of HTML content stored in component description fields within the Autodesk Fusion desktop application, which renders user-supplied markup in a context that allows script execution. Because Fusion is a desktop application (likely using an embedded web rendering engine such as Electron or a WebView), stored XSS can escape typical browser sandboxing constraints and interact with the local filesystem or execute native code. Exploitation requires user interaction — specifically, a victim must click on a maliciously crafted component description — but no authentication or elevated privileges are required of the attacker to plant the payload (Autodesk Advisory).

Impact

Successful exploitation allows a malicious actor to read sensitive local files accessible to the Fusion process and execute arbitrary code with the privileges of the current user running the application (Autodesk Advisory, NVD). The CVSS assessment reflects high confidentiality and high integrity impact, with no availability impact. In a design or engineering environment where Autodesk Fusion is commonly used, exploitation could expose proprietary CAD/design files, credentials stored locally, or enable further lateral movement if the attacker achieves persistent code execution on the victim's workstation.

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.008% (0.000080), indicating a very low probability of exploitation in the near term. Exploitation requires an attacker to first store a malicious payload in a component description accessible to the target user, which may require some level of access to shared Fusion project resources.

Exploitation steps

  1. Craft malicious payload: Prepare a malicious HTML/JavaScript payload designed to read local files or execute system commands via the Fusion application's embedded rendering engine (e.g., using Node.js APIs if Electron-based, or file:// URI schemes).
  2. Embed payload in component description: Gain access to a shared Autodesk Fusion project or component (e.g., through a compromised account, supply chain access, or a shared collaboration workspace) and insert the crafted HTML payload into a component's description field.
  3. Deliver to victim: Share the malicious component or project with the target user, or wait for the target to open a shared project containing the poisoned component.
  4. Trigger execution: When the victim clicks on the component description within the Fusion desktop application, the stored XSS payload is rendered and executed in the context of the Fusion process.
  5. Achieve objective: The executed payload reads local files (e.g., credentials, design files, configuration data) or spawns arbitrary code/processes with the privileges of the Fusion application user, potentially enabling data exfiltration or further system compromise (Autodesk Advisory, NVD).

Indicators of compromise

  • File System: Unexpected file reads or copies of sensitive files (e.g., SSH keys, browser credential stores, design files) from directories accessible to the Fusion process; new or modified files in Fusion's working directories.
  • Process: Unusual child processes spawned by the Autodesk Fusion process (e.g., cmd.exe, powershell.exe, bash, curl, python) that are not part of normal Fusion operation.
  • Network: Unexpected outbound network connections from the Fusion process to external or unknown IP addresses, particularly shortly after a user interacts with a component description.
  • Logs: Application or system logs showing Fusion accessing file paths outside its normal working directories; OS-level audit logs recording file access events initiated by the Fusion process for sensitive files.

Mitigation and workarounds

Autodesk has released a patch in Fusion version 2606.1.21, which resolves this vulnerability; all users running earlier versions should update immediately (Autodesk Advisory). Updated installers are available via the Autodesk Fusion Client Downloader for both Windows and macOS. As interim mitigations, users should exercise caution when opening component descriptions from untrusted or external sources, restrict Fusion project sharing to trusted collaborators, and monitor for suspicious process or file activity on systems running Fusion.

Community reactions

The vulnerability was noted in a CISA weekly vulnerability bulletin (week of January 19, 2026) and picked up by security aggregators including Red Packet Security and VulnDB (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard CVE tracking and aggregation activity. The low EPSS score and absence of public PoC suggest limited community concern at this time.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management