SimStudioAI sim route.ts handleLocalFile path traversal

CVE Details

Basic Information

Title SimStudioAI sim route.ts handleLocalFile path traversal
Type cve
Published 2025-07-07T02:02:07.997Z
Modified 2025-07-07T02:02:07.997Z

Product Information

Vendor SimStudioAI
Product sim
Version 0.1.0

CVSS Information

Base Score 6.9 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Affected Products

  • SimStudioAI sim 0.1.0
  • SimStudioAI sim 0.1.1
  • SimStudioAI sim 0.1.2
  • SimStudioAI sim 0.1.3
  • SimStudioAI sim 0.1.4
  • SimStudioAI sim 0.1.5
  • SimStudioAI sim 0.1.6
  • SimStudioAI sim 0.1.7
  • SimStudioAI sim 0.1.8
  • SimStudioAI sim 0.1.9
  • SimStudioAI sim 0.1.10
  • SimStudioAI sim 0.1.11
  • SimStudioAI sim 0.1.12
  • SimStudioAI sim 0.1.13
  • SimStudioAI sim 0.1.14
  • SimStudioAI sim 0.1.15
  • SimStudioAI sim 0.1.16
  • SimStudioAI sim 0.1.17

Additional Information

CWE List CWE-22
Source VulDB

Description

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.