Double Free Vulnerability in Rapsody by Schneider Electric
CVE-2025-13844
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 15 January 2026
What is CVE-2025-13844?
A double free vulnerability in Rapsody may lead to heap memory corruption when users import a malicious SSD project file shared by attackers. This flaw can potentially be exploited to manipulate memory allocation, leading to unexpected behavior or system crashes. It is crucial for users to implement security measures to mitigate the risk associated with importing unverified project files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EcoStruxure Power Build Rapsody FR v2.8.1 and prior
EcoStruxure Power Build Rapsody INT v2.8.6 and prior
EcoStruxure Power Build Rapsody ES v2.8.5 and prior
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved