
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10244 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application that allows a malicious actor to execute arbitrary code or read local files when a crafted HTML payload is rendered by the application. It affects Autodesk Fusion versions from 2602.1.25 up to (but not including) 2604.1.25. The vulnerability was published on September 23, 2025, with a patch made available on December 1, 2025. It carries a CVSS v3.1 base score of 8.7 (High) (Autodesk Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored variant. When the Autodesk Fusion desktop application renders a maliciously crafted HTML payload, it fails to properly sanitize or encode the content, allowing injected scripts to execute within the application's process context. Exploitation requires low privileges and user interaction (e.g., a victim opening or viewing the malicious content), but the scope is changed — meaning the impact extends beyond the originating component. No public proof-of-concept code has been identified (Autodesk Advisory).
Successful exploitation can allow an attacker to read local files from the victim's system or execute arbitrary code within the context of the Autodesk Fusion process, compromising both confidentiality and integrity. The changed scope indicates that the vulnerability's effects can extend beyond the application itself, potentially exposing sensitive design data or system files accessible to the Fusion process. Availability is not directly impacted, but unauthorized code execution could facilitate further compromise or data exfiltration (Autodesk Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in a vulnerability bulletin for the week of September 22, 2025. Exploitation requires an attacker with low privileges to deliver a crafted HTML payload that a victim must render within the Fusion application (Autodesk Advisory, CISA Bulletin).
cmd.exe, powershell.exe, bash, curl, or scripting interpreters).Autodesk has released a patched version of Fusion; users should update to version 2604.1.25 or later to remediate the vulnerability. As interim measures, users should avoid opening Autodesk Fusion project files or HTML content received from untrusted or unknown sources. Implementing least-privilege principles for the Fusion application and monitoring for suspicious process or network activity can reduce risk until patching is complete (Autodesk Advisory).
The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of September 22, 2025, and picked up by several security aggregators including Red Packet Security, VulnDB, and INCIBE-CERT. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking and aggregation (CISA Bulletin, Red Packet Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."