A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
References
Configurations
History
24 Jun 2026, 15:30
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Autodesk fusion
Autodesk |
|
| CPE | cpe:2.3:a:autodesk:fusion:*:*:*:*:*:*:*:* | |
| References | () https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.dmg - Product | |
| References | () https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.exe - Product | |
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0008 - Vendor Advisory, Patch |
22 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 18:16
Updated : 2026-06-24 15:30
NVD link : CVE-2026-10789
Mitre link : CVE-2026-10789
CVE.ORG link : CVE-2026-10789
JSON object : View
Products Affected
autodesk
- fusion
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
