{"id":"CVE-2025-31365","title":"An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via trick…","summary":"An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via trick…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","cwe":["CWE-94"],"vendor":"fortinet","product":"forticlient","affected":["forticlient >= 7.2.1, < 7.2.9","forticlient >= 7.4.0, < 7.4.4"],"patched":["forticlient 7.4.4"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31365","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-037","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00277,"epssPercentile":0.18457,"ingestedAt":"2026-10-08T11:31:27.388Z","slug":"CVE-2025-31365","body":"## Overview\n\nAn Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.\n\n## Affected\n\n- `forticlient >= 7.2.1, < 7.2.9`\n- `forticlient >= 7.4.0, < 7.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `forticlient 7.4.4`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}