IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-627195: Zip Path Traversal Vulnerability in Mendix Studio Pro's Module Installation Process

MEDIUM
CVSS 6.1
Date 2026-09-28T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-40592 6.1 medium
CVE-2025-40592. A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.

// Remediations (16)

Patch: Update to V11.13.0 or later version
Update to V11.13.0 or later version
Mitigation: Do not install untrusted/unverified modules in your Studio Pro projects
Do not install untrusted/unverified modules in your Studio Pro projects
Patch: Update to V9.24.44 or later version
Update to V9.24.44 or later version
Patch: Update to V11.6.9 or later version
Update to V11.6.9 or later version
Patch: Update to V10.24.24 or later version
Update to V10.24.24 or later version
Patch: Update to V9.24.35 or later version
Update to V9.24.35 or later version
Patch: Update to V11.12.2 or later version
Update to V11.12.2 or later version
Patch: Update to V8.18.35 or later version
Update to V8.18.35 or later version
Patch: Update to V10.6.24 or later version
Update to V10.6.24 or later version
Patch: Update to V10.23.0 or later version
Update to V10.23.0 or later version
Patch: Update to V10.18.7 or later version
Update to V10.18.7 or later version
Patch: Update to V8.18.35 or later version
Update to V8.18.35 or later version
Patch: Update to V9.24.35 or later version
Update to V9.24.35 or later version
Mitigation: Do not install untrusted/unverified modules in your Studio Pro projects
Do not install untrusted/unverified modules in your Studio Pro projects
Patch: Update to V11.0.0 or later version
Update to V11.0.0 or later version
Patch: Update to V10.12.17 or later version
Update to V10.12.17 or later version

// References