Junglewise Threat Intelligence

CVE-2025-13845: Schneider Electric Rapsody use-after-free in project file parsing

CVE-2025-13845 · Severity: high · CVSS 7.8 · Published 2026-01-15

Vendors: Schneider Electric.

Executive brief

Rapsody is a systems modeling and requirements management tool used by engineering teams to design and document complex systems. A use-after-free vulnerability allows attackers to execute arbitrary code by crafting a malicious project file (SSD format) that, when imported by an unsuspecting user, triggers memory corruption and enables remote code execution on the user's workstation.

Technical details

CVE-2025-13845 is a use-after-free (CWE-416) vulnerability in Schneider Electric Rapsody's project file import functionality. The flaw occurs in the SSD file parser, where freed memory is accessed after deallocation, allowing memory corruption. The attack requires no authentication but depends on user interaction: the victim must manually import a crafted malicious SSD project file. Successful exploitation grants arbitrary code execution in the context of the Rapsody application with the privileges of the importing user. No patch information is currently available in the advisory references.

Affected products

  • Schneider Electric Rapsody

Timeline

  • 2026-01-15: disclosed

References