A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
References
Configurations
History
No history.
Information
Published : 2026-06-22 18:16
Updated : 2026-06-24 15:30
NVD link : CVE-2026-10789
Mitre link : CVE-2026-10789
CVE.ORG link : CVE-2026-10789
JSON object : View
Products Affected
autodesk
- fusion
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
