📦 Sim

by Sim

🔍 What is Sim?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-3431

CRITICAL CVSS 9.8 Mar 2, 2026

SimStudio versions below 0.5.74 have MongoDB tool endpoints that accept arbitrary connection parameters without authentication or host restrictions. This allows attackers to connect to any reachable M...

CVE-2025-15099

HIGH CVSS 7.3 Dec 26, 2025

This vulnerability allows remote attackers to bypass authentication in simstudioai sim by manipulating the INTERNAL_API_SECRET argument in the CRON Secret Handler component. Attackers can potentially ...

CVE-2025-7114

HIGH CVSS 7.3 Jul 7, 2025

This critical vulnerability in SimStudioAI allows unauthenticated remote attackers to bypass authentication and upload files via the session handler API. It affects all SimStudioAI installations up to...

CVE-2025-10097

MEDIUM CVSS 6.3 Sep 8, 2025

This vulnerability allows remote attackers to execute arbitrary code on SimStudioAI sim servers by injecting malicious code through the 'code' parameter in the execute route API. It affects all users ...

CVE-2025-10096

MEDIUM CVSS 6.3 Sep 8, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in SimStudioAI sim software up to version 1.0.0. Attackers can manipulate the filePath parameter in the route.ts API endpoint to m...

CVE-2025-9800

MEDIUM CVSS 6.3 Sep 1, 2025

This vulnerability allows remote attackers to upload arbitrary files to SimStudioAI sim applications due to insufficient validation in the HTML File Parser component. Attackers can exploit this to pot...

CVE-2025-9801

MEDIUM CVSS 5.4 Sep 1, 2025

This CVE describes a path traversal vulnerability in SimStudioAI sim software where manipulation of the filePath argument allows attackers to access files outside the intended directory. Remote exploi...