Unrated severityNVD Advisory· Published Jun 22, 2026· Updated Jun 22, 2026
MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop
CVE-2026-10789
Description
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
Affected products
1Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.