Code Injection in Fusion 360 - CVE-2025-10244

 

Code Injection in Fusion 360 - CVE-2025-10244

Published: September 23, 2025


Vulnerability identifier: #VU116032
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-10244
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to execute arbitrary JavaScript code on the system.

The vulnerability exists due to insufficient sanitization of user-supplied data when rendered by the Autodesk Fusion desktop application. A remote attacker can inject and execute arbitrary HTML and script code in the context of the desktop application and gain access to sensitive information. 


Affected software

Fusion 360

How to mitigate CVE-2025-10244

Install updates from vendor's website.

Fusion 360 - update to 2604.1.25

External References

Related Security Bulletins