CVE-2025-40592: Path Traversal
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Studio Pro 10.18 (All versions < V10.18.7), Mendix Studio Pro 10.6 (All versions < V10.6.24), Mendix Studio Pro 11 (All versions < V11.0.0), Mendix Studio Pro 8 (All versions < V8.18.35), Mendix Studio Pro 9 (All versions < V9.24.35). A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40592?
CVE-2025-40592 has been classified as a high severity vulnerability affecting multiple versions of Mendix Studio Pro.
How do I fix CVE-2025-40592?
To fix CVE-2025-40592, upgrade Mendix Studio Pro to version 10.23.0 or later, or apply the relevant patches for the affected versions.
Which versions of Mendix Studio Pro are affected by CVE-2025-40592?
CVE-2025-40592 affects all versions of Mendix Studio Pro below 10.23.0, as well as other older versions listed in the CVE description.
What are the potential impacts of CVE-2025-40592?
Exploitation of CVE-2025-40592 may lead to unauthorized access or manipulation of applications developed with affected versions of Mendix Studio Pro.
Has CVE-2025-40592 been publicly disclosed?
Yes, CVE-2025-40592 has been publicly disclosed and is listed in the national vulnerability database.