CVE-2026-105043
3.6
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Summary
MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MathWorks | Simulink | 0 < R2026b | affected |
Weaknesses
- CWE-451: CWE-451 User Interface (UI) Misrepresentation of Critical Information
References
- https://www.mathworks.com/products/simulink.html
- https://alexanderboll.dev/disclosures/simulink-vulnerability-concealed-blocks/
- https://www.mathworks.com/help/simulink/release-notes.html#mw_81eb54b6-4dfa-42c1-8c3c-e998eff5a8cd
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.