Unrated severityNVD Advisory· Published Sep 23, 2025· Updated Feb 26, 2026
HTML Payload Stored Cross-Site Scripting (XSS) Vulnerability
CVE-2025-10244
Description
A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross-site Scripting (XSS) vulnerability. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.