Impact
The flaw occurs because Mendix Studio Pro does not validate project files that are processed during the build pipeline. An attacker can craft a malicious project file that, when opened and executed by a user, causes arbitrary code to run with the same privileges as that user. This represents a code‑execution vulnerability (CWE‑94).
Affected Systems
Affected versions are all releases of Mendix Studio Pro from 10.11 through 11.9, with specific breakpoints: versions earlier than 10.24.21 and 11.6.7 are vulnerable. The product is developed by Siemens.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation. Because the issue requires a user to open a malicious project file locally, the likelihood of successful exploitation relies on social engineering, implying a moderate exploitability. The attack vector is local and requires a user to execute the malicious file. No network‑based vector is described.
OpenCVE Enrichment