Executive brief
Mendix Studio Pro is a development environment used to build business applications. A security flaw allows an attacker to create a malicious project file that, if opened and run by a developer, can execute unauthorized commands on their computer. This could lead to a full compromise of the developer's workstation and any data they have access to.
Technical details
A code injection vulnerability (CWE-94) exists in Mendix Studio Pro due to improper validation and sanitization of project files during the build pipeline. The vulnerability is triggered when the application parses a specially crafted malicious project file. An attacker requires high privileges and user interaction (tricking a user into opening and running the project) to achieve arbitrary code execution in the context of the local user. Siemens has released patches for versions 10.24 (V10.24.21) and 11.6 (V11.6.7), while other versions currently have no planned fix.
Affected products
- Siemens Mendix Studio Pro 10.11 through 10.23 All versions
- Siemens Mendix Studio Pro 10.24 versions < V10.24.21
- Siemens Mendix Studio Pro 11.0 through 11.5 All versions
- Siemens Mendix Studio Pro 11.6 versions < V11.6.7
- Siemens Mendix Studio Pro 11.7 through 11.11 All versions
Timeline
- 2026-06-30: disclosed: Initial advisory publication by Siemens and NVD.
- 2026-06-30: patched: Fixes released for versions 10.24.21 and 11.6.7.