CVE-2025-10244

8.7

Autodesk · Fusion

Autodesk Fusion is vulnerable to stored cross-site scripting (XSS) via maliciously crafted HTML payloads, potentially allowing local file access or arbitrary code execution.

Executive summary

A stored cross-site scripting vulnerability in Autodesk Fusion creates a high-severity risk of arbitrary code execution or unauthorized local file access.

Vulnerability

This is a stored cross-site scripting (XSS) flaw (CWE-79) triggered when the application renders a maliciously crafted HTML payload. The vulnerability requires an authenticated user with low privileges to interact with the malicious content, which subsequently executes within the context of the current process.

Business impact

Successful exploitation allows an attacker to bypass standard security boundaries, leading to potential disclosure of sensitive local files or the execution of unauthorized code. Given the CVSS score of 8.7, this is a high-severity threat that could lead to full system compromise if an attacker gains control over the user session. Such an event would result in significant data loss, intellectual property theft, and potential disruption of engineering workflows.

Remediation

Immediate Action: Update the Autodesk Fusion desktop application to version 2604.1.25 or later as specified in the vendor security advisory.

Proactive Monitoring: Review application logs for unusual HTML content or unexpected script execution patterns within the local environment.

Compensating Controls: Ensure that endpoint security solutions are configured to detect and block suspicious child processes spawned by the Autodesk Fusion executable.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for arbitrary code execution. Administrators should prioritize the deployment of the vendor-provided update across all workstations running the affected versions of Autodesk Fusion to eliminate the attack surface immediately.

More Autodesk CVEs

Sources