Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. | |
| Title | MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop | |
| First Time appeared |
Autodesk
Autodesk fusion |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:autodesk:fusion:2703.1.11:*:*:*:*:*:*:* | |
| Vendors & Products |
Autodesk
Autodesk fusion |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: autodesk
Published:
Updated: 2026-06-23T03:56:02.324Z
Reserved: 2026-06-03T19:23:28.312Z
Link: CVE-2026-10789
Updated: 2026-06-22T17:25:24.990Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T21:15:04Z