CVE-2024-29154: Danielmiessler Fabric

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.

Affected products

Published 2024-03-18. Last modified 2026-06-17.