Executive brief
Autodesk Fusion is a professional 3D design and engineering software. A security flaw in its MCP extension allows an attacker to take control of a user's computer if the user visits a malicious website while the application is running. This could lead to the theft of sensitive design data, installation of malware, or full system compromise under the user's account permissions.
Technical details
A code injection vulnerability (CWE-94) exists in the MCP extension of Autodesk Fusion Desktop. The flaw is triggered when a user with the application running and the extension enabled visits a maliciously crafted webpage. This suggests a lack of proper input validation or origin checking for requests handled by the extension's local communication mechanism. An attacker can achieve arbitrary code execution with the privileges of the logged-in user. The vulnerability is tracked as CVE-2026-10789 and has a CVSS score of 9.6, reflecting its high impact and remote reachability, though it requires user interaction (visiting a site).
Affected products
- Autodesk Fusion Desktop 2703.1.11 to 2703.1.20
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory