CVE-2025-31365
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrar
Severity
Medium 5.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
20.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet
Description
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.
Weakness: CWE-94
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiClientMac
Credit
Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.9 or above