High severity7.1NVD Advisory· Published Apr 14, 2026· Updated Apr 22, 2026
CVE-2026-4345
CVE-2026-4345
Description
A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
7- PoC Code Published for Critical NGINX VulnerabilitySecurityWeek · May 16, 2026
- F5 Patches Over 50 VulnerabilitiesSecurityWeek · May 14, 2026
- High-Severity Vulnerability Patched in VMware FusionSecurityWeek · May 14, 2026
- 1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress PluginWordfence Blog · May 12, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)Wordfence Blog · Apr 23, 2026
- Oracle April 2026 Critical Patch Update Addresses 241 CVEsTenable Blog · Apr 21, 2026
- Agents that remember: introducing Agent MemoryCloudflare Blog · Apr 17, 2026