CVE-2025-40592

Executive Summary

A zip path traversal flaw in Mendix Studio Pro’s module installation allows an attacker to craft a malicious module (e.g., via the Mendix Marketplace) that writes or modifies arbitrary files outside the developer’s project directory. Affected versions include all Studio Pro 9, 10, 11, and 11.12 releases prior to the specified patch levels. This vulnerability can lead to unauthorized file manipulation, potentially compromising application integrity and confidentiality.


Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2025-06-12T08:15:23.407 - Last Modified: 2026-09-28T10:16:40.363

Original Description: A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Windows), Mendix Studio Pro 11.12 (All versions < V11.12.2 for Mac), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Windows), Mendix Studio Pro 11.6 (All versions < V11.6.9 for Mac), Mendix Studio Pro 9 (All versions < V9.24.44 for Windows). A zip path traversal vulnerability exists in the module installation process of Studio Pro. By crafting a malicious module and distributing it via (for example) the Mendix Marketplace, an attacker could write or modify arbitrary files in directories outside a developer’s project directory upon module installation.

"Know, first, who you are, and then adorn yourself accordingly."

— Epictetus
Source: NVD