CVE-2025-31365

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrar

Severity
Medium 5.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
18.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet

Description

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.

Weakness: CWE-94

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientMac

Credit

Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiClientMac version 7.4.4 or above Upgrade to FortiClientMac version 7.2.9 or above

Something wrong here?