#VU121954 Stored cross-site scripting in Fusion 360 - CVE-2026-0533
Published: January 22, 2026
Fusion 360
Autodesk
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in a design name when displayed during the delete confirmation dialog and clicked by a user. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.