๐Ÿ” CVE Alert

CVE-2026-44541

UNKNOWN 0.0

Fides: DOM-based XSS vulnerability in fides.js via fides_description override

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.

CWE CWE-79
Vendor ethyca
Product fides
Published Jun 8, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for ethyca fides

Be the first to know when new unknown vulnerabilities affecting ethyca fides are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ethyca / fides
>= 2.33.0, < 2.84.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ethyca/fides/security/advisories/GHSA-5qrq-9645-g5g2 github.com: https://github.com/ethyca/fides/commit/67e43b10b1096c7f84d5c0eeba08ee3b7846b7cd github.com: https://github.com/ethyca/fides/releases/tag/2.84.5