#VU121956 Stored cross-site scripting in Fusion 360 - CVE-2026-0535
Published: January 22, 2026
Fusion 360
Autodesk
Description
The disclosed vulnerability allows a remote user cker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data stored in a component’s description. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.