CVE-2025-40592
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
Summary
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Windows), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Mac), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Windows), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Mac), Mendix Studio Pro 9 (All versions < V9.24.44 for Windows). A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Siemens | Mendix Studio Pro 10 | 0 < V10.24.24 | affected |
| Siemens | Mendix Studio Pro 10 | 0 < V10.24.24 | affected |
| Siemens | Mendix Studio Pro 11 | 0 < V11.13.0 | affected |
| Siemens | Mendix Studio Pro 11 | 0 < V11.13.0 | affected |
| Siemens | Mendix Studio Pro 11.12 | 0 < V11.12.2 | affected |
| Siemens | Mendix Studio Pro 11.12 | 0 < V11.12.2 | affected |
| Siemens | Mendix Studio Pro 11.6 | 0 < V11.6.9 | affected |
| Siemens | Mendix Studio Pro 11.6 | 0 < V11.6.9 | affected |
| Siemens | Mendix Studio Pro 9 | 0 < V9.24.44 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.