#VU125984 Stored cross-site scripting in Fusion 360 - CVE-2026-4344
Published: April 14, 2026
Fusion 360
Autodesk
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when displayed during the delete confirmation dialog. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.