CVE-2023-46126Low· 3.9▾ SunlitFides JavaScript Injection Vulnerability in Privacy Center URL
▾ Sunlit zone — Low / medium · no exploitation signal
impact 21.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
Last analysed / modified upstream
The Fides web application allows users to edit consent and privacy notices such as cookie banners. These privacy notices can then be served by other integrated websites, for example in cookie consent banners. One of the editable fields is a privacy policy URL and this input was found to not be validated.
The vulnerability makes it possible to craft a payload in the privacy policy URL which triggers JavaScript execution when the privacy notice is served by an integrated website. The domain scope of the executed JavaScript is that of the integrated website.
Exploitation is limited to Admin UI users with the contributor role or higher.
The vulnerability has been patched in Fides version 2.22.1. Users are advised to upgrade to this version or later to secure their systems against this threat.
There are no workarounds.
ethyca-fides < 2.22.1Upgrade to a patched release:
ethyca-fides 2.22.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-46125Medium· 6.5Fides Information Disclosure Vulnerability in Config API Endpoint
CVE-2023-46124High· 8.2Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
CVE-2023-36827High· 7.5ethyca-fides Webserver API Path Traversal vulnerability
CVE-2026-42303MediumEthyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-44541Highethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
CVE-2024-52008Medium· 5.7Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API