Description
MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
Published: 2026-10-02
Score: 3.6 Low
EPSS: n/a
KEV: No
Impact: Code Execution
Action: Immediate Patch
AI Analysis

Impact

MathWorks Simulink before R2026b contains a flaw that allows attacker to craft a .slx file with blocks that are invisible in the editor yet trigger code execution when the file is opened. This flaw is categorized as a concealment vulnerability (CWE‑451). The CVSS score of 3.6 indicates a low overall severity, but the impact of executing arbitrary code within the modeling environment can still be significant for users who trust the file source.

Affected Systems

The vulnerability affects all installations of MathWorks Simulink released prior to version R2026b. No specific sub‑versions are listed, but any product that has not been upgraded to R2026b may be vulnerable.

Risk and Exploitability

The vulnerability enables code execution in the Simulink Editor when a crafted .slx file is opened. An attacker would need to supply a malicious file, for example via a file share or other means, and a user would need to open it. While an exploit has not been publicly documented, the flaw in the file parsing logic and lack of additional authentication barriers suggest that the risk of successful exploitation cannot be ruled out.

Generated by OpenCVE AI on October 2, 2026 at 22:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Simulink to R2026b or later, following MathWorks product release notes and advisories.
  • Verify the origin of any .slx file before opening it; treat files from untrusted or unknown sources as potentially malicious.
  • If an upgrade is not immediately possible, consider disabling automatic activation of hidden blocks or restricting code generation for unknown files, and monitor script logs for unexpected execution.

Generated by OpenCVE AI on October 2, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Title Simulink Hidden Blocks Trigger Code Execution

Fri, 02 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T21:34:14.561Z

Reserved: 2026-10-02T21:34:13.754Z

Link: CVE-2026-105043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T22:16:54.227

Modified: 2026-10-02T22:16:54.227

Link: CVE-2026-105043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:00:16Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information