Vulnerability Description
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
Related Weaknesses (CWE)
References
- https://github.com/ethyca/fides/commit/67e43b10b1096c7f84d5c0eeba08ee3b7846b7cd
- https://github.com/ethyca/fides/releases/tag/2.84.5
- https://github.com/ethyca/fides/security/advisories/GHSA-5qrq-9645-g5g2
- https://github.com/ethyca/fides/security/advisories/GHSA-5qrq-9645-g5g2
FAQ
What is CVE-2026-44541?
CVE-2026-44541 is a documented vulnerability. Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue ha...
How severe is CVE-2026-44541?
CVSS scoring is not yet available for CVE-2026-44541. Check NVD for updates.
Is there a patch for CVE-2026-44541?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.