CVE-2025-10244
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-10244 is a Stored Cross-Site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application that allows a malicious actor to execute arbitrary code or read local files when a crafted HTML payload is rendered by the application. It affects Autodesk Fusion versions from 2602.1.25 up to (but not including) 2604.1.25. The vulnerability was published on September 23, 2025, with a patch made available on December 1, 2025. It carries a CVSS v3.1 base score of 8.7 (High) (Autodesk Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored variant. When the Autodesk Fusion desktop application renders a maliciously crafted HTML payload, it fails to properly sanitize or encode the content, allowing injected scripts to execute within the application's process context. Exploitation requires low privileges and user interaction (e.g., a victim opening or viewing the malicious content), but the scope is changed — meaning the impact extends beyond the originating component. No public proof-of-concept code has been identified (Autodesk Advisory).

Impact

Successful exploitation can allow an attacker to read local files from the victim's system or execute arbitrary code within the context of the Autodesk Fusion process, compromising both confidentiality and integrity. The changed scope indicates that the vulnerability's effects can extend beyond the application itself, potentially exposing sensitive design data or system files accessible to the Fusion process. Availability is not directly impacted, but unauthorized code execution could facilitate further compromise or data exfiltration (Autodesk Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in a vulnerability bulletin for the week of September 22, 2025. Exploitation requires an attacker with low privileges to deliver a crafted HTML payload that a victim must render within the Fusion application (Autodesk Advisory, CISA Bulletin).

Exploitation steps

  1. Craft malicious payload: An attacker with low-level access (e.g., a collaborator or shared project contributor) crafts a malicious HTML payload containing a stored XSS script designed to read local files or execute commands within the Fusion process context.
  2. Inject payload: The attacker embeds the crafted HTML content into a shared Autodesk Fusion project, file, or collaborative workspace that will be rendered by the target's Fusion desktop application.
  3. Trigger rendering: The victim opens or views the malicious content within the Autodesk Fusion desktop application, causing the application to render the HTML payload without proper sanitization.
  4. Achieve objective: The injected script executes within the Fusion application's process context, enabling the attacker to read local files accessible to the process or execute arbitrary code, potentially exfiltrating sensitive design data or establishing further access (Autodesk Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Autodesk Fusion process (e.g., cmd.exe, powershell.exe, bash, curl, or scripting interpreters).
  • File System: Unusual file read activity targeting sensitive directories (e.g., user home directories, credential stores) initiated by the Fusion process; unexpected files written to disk by the Fusion application.
  • Network: Outbound network connections from the Autodesk Fusion process to unknown or suspicious external IP addresses or domains, particularly following the opening of shared project files.
  • Logs: Application or system logs showing anomalous script execution or file access events originating from the Fusion process context.

Mitigation and workarounds

Autodesk has released a patched version of Fusion; users should update to version 2604.1.25 or later to remediate the vulnerability. As interim measures, users should avoid opening Autodesk Fusion project files or HTML content received from untrusted or unknown sources. Implementing least-privilege principles for the Fusion application and monitoring for suspicious process or network activity can reduce risk until patching is complete (Autodesk Advisory).

Community reactions

The vulnerability was noted in CISA's weekly vulnerability bulletin for the week of September 22, 2025, and picked up by several security aggregators including Red Packet Security, VulnDB, and INCIBE-CERT. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking and aggregation (CISA Bulletin, Red Packet Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-bdb
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management