CVE-2025-40592
Description
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Windows), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Mac), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Windows), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Mac), Mendix Studio Pro 9 (All versions < V9.24.44 for Windows). A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: < V10.23.0, < V10.12.17, < V10.18.7, < V10.6.24, < V11.0.0, < V8.18.35, < V9.24.35
- Range: < V10.23.0, < V10.12.17, < V10.18.7, < V10.6.24, < V11.0.0, < V8.18.35, < V9.24.35
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.