Stored cross-site scripting in Fusion 360 - CVE-2026-0535
Published: January 22, 2026
Fusion 360
Detailed vulnerability description
The disclosed vulnerability allows a remote user cker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data stored in a component’s description. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.