Full Report
Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Arbitrary Code Execution in Mendix Studio Pro Build Pipeline
## CVE Details
- **CVE ID:** CVE-2026-48192
- **CVSS Score:**
- **CVSS v4.0:** 6.8 (Medium)
- **CVSS v3.1:** 5.4 (Medium)
- **CWE:** CWE-94: Improper Control of Generation of Code ('Code Injection')
## Affected Systems
- **Products:** Mendix Studio Pro (Low-code IDE)
- **Versions:**
- Versions before V11.12
- Specifically identified:
- Series 10: V10.11 through V10.23 (No fix planned); V10.24 < V10.24.21
- Series 11: V11.0 through V11.5 and V11.7 through V11.11 (No fix planned); V11.6 < V11.6.7
- **Configurations:** Systems where Mendix Studio Pro is used to open and process project files during a build pipeline.
## Vulnerability Description
Affected versions of Mendix Studio Pro fail to properly validate or sanitize project files when they are processed during the build pipeline. This file parsing flaw occurs when the application reads a specially crafted malicious project. Because the application does not adequately restrict the generation of code from these inputs, an attacker can achieve code injection.
## Exploitation
- **Status:** Not specified as exploited in the wild; PoC availability not mentioned.
- **Complexity:** High (Requires the creation of a specifically crafted project and user interaction).
- **Attack Vector:** Network (The malicious project would likely be delivered via network/remote means).
- **Required User Interaction:** Required (User must be tricked into opening and running the malicious project locally).
## Impact
- **Confidentiality:** None (Based on CVSS:3.1/VC:N)
- **Integrity:** High (Allows for unauthorized modification and arbitrary code execution)
- **Availability:** None (Based on CVSS:3.1/VA:N)
- **Context:** Code execution occurs in the security context of the user running the Studio Pro application.
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **Mendix Studio Pro 10.24:** Update to V10.24.21 or later.
- **Mendix Studio Pro 11.6:** Update to V11.6.7 or later.
- **Mendix Studio Pro 11.12:** Update to V11.12 or later (General fix version).
### Workarounds
- For versions where no fix is currently planned, Siemens recommends following general industrial security guidelines.
- Only open Mendix projects from trusted and known sources.
- Apply strict access controls to the build environment.
## Detection
- **Indicators of Compromise:** Unusual outbound network traffic or unexpected process spawning from the Mendix Studio Pro parent process during a build.
- **Detection Methods:** Monitor for the creation of suspicious files or execution of scripts in the context of the developer's workstation during project builds.
## References
- **Vendor Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/html/ssa-779310[.]html
- **Mendix Release Notes (10.24):** hxxps[://]docs[.]mendix[.]com/releasenotes/studio-pro/10[.]24/
- **Mendix Release Notes (11.6):** hxxps[://]docs[.]mendix[.]com/releasenotes/studio-pro/11[.]6/
- **Siemens Operational Guidelines:** hxxps[://]www[.]siemens[.]com/cert/operational-guidelines-industrial-security