---
id: CVE-2025-40592
title: >-
  A vulnerability has been identified in Mendix Studio Pro 10 (All versions <
  V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for
  Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix
  Studio Pro 11…
summary: >-
  A vulnerability has been identified in Mendix Studio Pro 10 (All versions <
  V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for
  Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix
  Studio Pro 11…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N'
cwe:
  - CWE-22
vendor: Siemens
product: Mendix Studio Pro 10
affected:
  - mendix_studio_pro_10 < V10.24.24
  - mendix_studio_pro_10 < V10.24.24
  - mendix_studio_pro_11 < V11.13.0
  - mendix_studio_pro_11 < V11.13.0
  - mendix_studio_pro_11.12 < V11.12.2
  - mendix_studio_pro_11.12 < V11.12.2
  - mendix_studio_pro_11.6 < V11.6.9
  - mendix_studio_pro_11.6 < V11.6.9
  - mendix_studio_pro_9 < V9.24.44
published: '2025-06-12'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T10:16:40.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40592'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-627195.html'
    label: productcert@siemens.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-06-12T13:55:58.769656Z'
epss: 0.00464
epssPercentile: 0.3769
ingestedAt: '2026-09-28T10:07:17.784Z'
---

## Overview

A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Windows), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Mac), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Windows), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Mac), Mendix Studio Pro 9 (All versions < V9.24.44 for Windows). A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
