PT-2026-41138 · Fides · Fides

CVE-2026-44541

·

Published

2026-05-14

·

Updated

2026-07-23

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Fides versions 2.33.0 through 2.84.4
Description A DOM-based Cross-Site Scripting (XSS) issue exists in fides.js, the script used to render consent banners. The problem occurs when the fides description variable is overridden via a URL query parameter, a JavaScript global, or a cookie on sites that have HTML-formatted descriptions enabled. In this configuration, the overridden value is rendered as live HTML without being processed by the server-side sanitizer, allowing an attacker to execute arbitrary JavaScript in the embedding site's origin. This can be triggered by a crafted link without authentication. If the payload is delivered via a cookie, it can persist and execute across all subdomains until the cookies are cleared.
Recommendations Update to version 2.84.5 or later. As a temporary workaround, set the FIDES PRIVACY CENTER ALLOW HTML DESCRIPTION environment variable to false on the Privacy Center container and redeploy to ensure HTML is stripped from descriptions.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44541
GHSA-5QRQ-9645-G5G2
PYSEC-2026-2470

Affected Products

Fides