PT-2026-41138 · Fides · Fides
CVE-2026-44541
·
Published
2026-05-14
·
Updated
2026-07-23
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Fides versions 2.33.0 through 2.84.4
Description
A DOM-based Cross-Site Scripting (XSS) issue exists in
fides.js, the script used to render consent banners. The problem occurs when the fides description variable is overridden via a URL query parameter, a JavaScript global, or a cookie on sites that have HTML-formatted descriptions enabled. In this configuration, the overridden value is rendered as live HTML without being processed by the server-side sanitizer, allowing an attacker to execute arbitrary JavaScript in the embedding site's origin. This can be triggered by a crafted link without authentication. If the payload is delivered via a cookie, it can persist and execute across all subdomains until the cookies are cleared.Recommendations
Update to version 2.84.5 or later.
As a temporary workaround, set the
FIDES PRIVACY CENTER ALLOW HTML DESCRIPTION environment variable to false on the Privacy Center container and redeploy to ensure HTML is stripped from descriptions.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fides