#VU116032 Code Injection in Fusion 360 - CVE-2025-10244
Published: September 23, 2025
Fusion 360
Autodesk
Description
The disclosed vulnerability allows a remote attacker to execute arbitrary JavaScript code on the system.
The vulnerability exists due to insufficient sanitization of user-supplied data when rendered by the Autodesk Fusion desktop application. A remote attacker can inject and execute arbitrary HTML and script code in the context of the desktop application and gain access to sensitive information.