IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Siemens Mendix Studio Pro

MEDIUM
CVSS 6.1
Date 2026-09-29T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-40592 6.1 medium
CVE-2025-40592. A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.

// Remediations (16)

Patch: Update to V11.13.0 or later version
Update to V11.13.0 or later version
Mitigation: Do not install untrusted/unverified modules in your Studio Pro projects
Do not install untrusted/unverified modules in your Studio Pro projects
Patch: Update to V9.24.44 or later version
Update to V9.24.44 or later version
Patch: Update to V11.6.9 or later version
Update to V11.6.9 or later version
Patch: Update to V10.24.24 or later version
Update to V10.24.24 or later version
Patch: Update to V9.24.35 or later version
Update to V9.24.35 or later version
Patch: Update to V11.12.2 or later version
Update to V11.12.2 or later version
Patch: Update to V8.18.35 or later version
Update to V8.18.35 or later version
Patch: Update to V11.6.9 or later version
Update to V11.6.9 or later version
Patch: Update to V11.13.0 or later version
Update to V11.13.0 or later version
Patch: Update to V11.12.2 or later version
Update to V11.12.2 or later version
Patch: Update to V8.18.35 or later version
Update to V8.18.35 or later version
Patch: Update to V9.24.35 or later version
Update to V9.24.35 or later version
Mitigation: Do not install untrusted/unverified modules in your Studio Pro projects
Do not install untrusted/unverified modules in your Studio Pro projects
Patch: Update to V9.24.44 or later version
Update to V9.24.44 or later version
Patch: Update to V10.24.24 or later version
Update to V10.24.24 or later version

// References