SimStudioAI sim Session route.ts POST missing authentication

CVE Details

Basic Information

Title SimStudioAI sim Session route.ts POST missing authentication
Type cve
Published 2025-07-07T05:32:05.686Z
Modified 2025-07-07T05:32:05.686Z

Product Information

Vendor SimStudioAI
Product sim
Version 37786d371e17d35e0764e1b5cd519d873d90d97b

CVSS Information

Base Score 6.9 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A critical vulnerability in SimStudioAI sim’s Session Handler allows unauthenticated remote attackers to exploit missing authentication in the POST function of route.ts. This could lead to unauthorized access. The vendor has not responded to the disclosure.
AI Severity Critical
AI Vendor SimStudioAI
AI Product SimStudioAI sim
AI Version 37786d371e17d35e0764e1b5cd519d873d90d97b

Affected Products

  • SimStudioAI sim 37786d371e17d35e0764e1b5cd519d873d90d97b

Additional Information

CWE List CWE-306, CWE-287
Source VulDB

Description

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of the file apps/sim/app/api/files/upload/route.ts of the component Session Handler. The manipulation of the argument Request leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.