Impact
MathWorks Simulink before R2026b contains a flaw that allows attacker to craft a .slx file with blocks that are invisible in the editor yet trigger code execution when the file is opened. This flaw is categorized as a concealment vulnerability (CWE‑451). The CVSS score of 3.6 indicates a low overall severity, but the impact of executing arbitrary code within the modeling environment can still be significant for users who trust the file source.
Affected Systems
The vulnerability affects all installations of MathWorks Simulink released prior to version R2026b. No specific sub‑versions are listed, but any product that has not been upgraded to R2026b may be vulnerable.
Risk and Exploitability
The vulnerability enables code execution in the Simulink Editor when a crafted .slx file is opened. An attacker would need to supply a malicious file, for example via a file share or other means, and a user would need to open it. While an exploit has not been publicly documented, the flaw in the file parsing logic and lack of additional authentication barriers suggest that the risk of successful exploitation cannot be ruled out.
OpenCVE Enrichment