#VU116032 Code Injection in Fusion 360 - CVE-2025-10244

 

#VU116032 Code Injection in Fusion 360 - CVE-2025-10244

Published: September 23, 2025


Vulnerability identifier: #VU116032
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-10244
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Fusion 360
Software vendor:
Autodesk

Description

The disclosed vulnerability allows a remote attacker to execute arbitrary JavaScript code on the system.

The vulnerability exists due to insufficient sanitization of user-supplied data when rendered by the Autodesk Fusion desktop application. A remote attacker can inject and execute arbitrary HTML and script code in the context of the desktop application and gain access to sensitive information. 


Remediation

Install updates from vendor's website.

External links