{"id":66745,"date":"2026-06-28T19:38:07","date_gmt":"2026-06-28T19:38:07","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=66745"},"modified":"2026-06-28T19:38:07","modified_gmt":"2026-06-28T19:38:07","slug":"simstudioai-sim-password-protection-deploymentts-weak-hash","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=66745","title":{"rendered":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps\/sim\/lib\/core\/security\/deployment.ts of the component Password Protection Handler. Performing a manipulation results in use of weak hash. The attack is possible to be carried out remotely. The attack&#8217;s complexity is rated as high. The exploitation appears to be difficult. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.&#8221;,&#8221;published&#8221;:&#8221;2026-06-28T22:15:11.256Z&#8221;,&#8221;modified&#8221;:&#8221;2026-06-28T22:15:11.256Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;SimStudioAI sim Password Protection deployment.ts weak hash&#8221;,&#8221;source&#8221;:&#8221;VulDB&#8221;,&#8221;references&#8221;:&#8221;https:\/\/vuldb.com\/vuln\/374518\\nhttps:\/\/vuldb.com\/vuln\/374518\/cti\\nhttps:\/\/vuldb.com\/cve\/CVE-2026-13510\\nhttps:\/\/vuldb.com\/submit\/838842\\nhttps:\/\/github.com\/simstudioai\/sim\/issues\/4759\\nhttps:\/\/github.com\/simstudioai\/sim\/pull\/4760\\nhttps:\/\/github.com\/simstudioai\/sim\/&#8221;,&#8221;id&#8221;:&#8221;CVE-2026-13510&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-328&#8243;,&#8221;CWE-327&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;SimStudioAI sim 0.6.0\\nSimStudioAI sim 0.6.1\\nSimStudioAI sim 0.6.2\\nSimStudioAI sim 0.6.3\\nSimStudioAI sim 0.6.4\\nSimStudioAI sim 0.6.5\\nSimStudioAI sim 0.6.6\\nSimStudioAI sim 0.6.7\\nSimStudioAI sim 0.6.8\\nSimStudioAI sim 0.6.9\\nSimStudioAI sim 0.6.10\\nSimStudioAI sim 0.6.11\\nSimStudioAI sim 0.6.12\\nSimStudioAI sim 0.6.13\\nSimStudioAI sim 0.6.14\\nSimStudioAI sim 0.6.15\\nSimStudioAI sim 0.6.16\\nSimStudioAI sim 0.6.17\\nSimStudioAI sim 0.6.18\\nSimStudioAI sim 0.6.19\\nSimStudioAI sim 0.6.20\\nSimStudioAI sim 0.6.21\\nSimStudioAI sim 0.6.22\\nSimStudioAI sim 0.6.23\\nSimStudioAI sim 0.6.24\\nSimStudioAI sim 0.6.25\\nSimStudioAI sim 0.6.26\\nSimStudioAI sim 0.6.27\\nSimStudioAI sim 0.6.28\\nSimStudioAI sim 0.6.29\\nSimStudioAI sim 0.6.30\\nSimStudioAI sim 0.6.31\\nSimStudioAI sim 0.6.32\\nSimStudioAI sim 0.6.33\\nSimStudioAI sim 0.6.34\\nSimStudioAI sim 0.6.35\\nSimStudioAI sim 0.6.36\\nSimStudioAI sim 0.6.37\\nSimStudioAI sim 0.6.38\\nSimStudioAI sim 0.6.39\\nSimStudioAI sim 0.6.40\\nSimStudioAI sim 0.6.41\\nSimStudioAI sim 0.6.42\\nSimStudioAI sim 0.6.43\\nSimStudioAI sim 0.6.44\\nSimStudioAI sim 0.6.45\\nSimStudioAI sim 0.6.46\\nSimStudioAI sim 0.6.47\\nSimStudioAI sim 0.6.48\\nSimStudioAI sim 0.6.49\\nSimStudioAI sim 0.6.50\\nSimStudioAI sim 0.6.51\\nSimStudioAI sim 0.6.52\\nSimStudioAI sim 0.6.53\\nSimStudioAI sim 0.6.54\\nSimStudioAI sim 0.6.55\\nSimStudioAI sim 0.6.56\\nSimStudioAI sim 0.6.57\\nSimStudioAI sim 0.6.58\\nSimStudioAI sim 0.6.59\\nSimStudioAI sim 0.6.60\\nSimStudioAI sim 0.6.61\\nSimStudioAI sim 0.6.62\\nSimStudioAI sim 0.6.63\\nSimStudioAI sim 0.6.64\\nSimStudioAI sim 0.6.65\\nSimStudioAI sim 0.6.66\\nSimStudioAI sim 0.6.67\\nSimStudioAI sim 0.6.68\\nSimStudioAI sim 0.6.69\\nSimStudioAI sim 0.6.70\\nSimStudioAI sim 0.6.71\\nSimStudioAI sim 0.6.72\\nSimStudioAI sim 0.6.73\\nSimStudioAI sim 0.6.74\\nSimStudioAI sim 0.6.75\\nSimStudioAI sim 0.6.76\\nSimStudioAI sim 0.6.77\\nSimStudioAI sim 0.6.78\\nSimStudioAI sim 0.6.79\\nSimStudioAI sim 0.6.80\\nSimStudioAI sim 0.6.81\\nSimStudioAI sim 0.6.82\\nSimStudioAI sim 0.6.83\\nSimStudioAI sim 0.6.84\\nSimStudioAI sim 0.6.85\\nSimStudioAI sim 0.6.86\\nSimStudioAI sim 0.6.87\\nSimStudioAI sim 0.6.88\\nSimStudioAI sim 0.6.89\\nSimStudioAI sim 0.6.90\\nSimStudioAI sim 0.6.91\\nSimStudioAI sim 0.6.92&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:6.3,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:H\/AT:N\/PR:N\/UI:N\/VC:L\/VI:N\/VA:N\/SC:N\/SI:N\/SA:N\/E:P&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;sim&#8221;,&#8221;version&#8221;:&#8221;0.6.0&#8243;,&#8221;vendor&#8221;:&#8221;SimStudioAI&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps\/sim\/lib\/core\/security\/deployment.ts of the component&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[6,8,23,12,21,13,7,11,5],"class_list":["post-66745","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-cve","tag-cvss","tag-cvss-63","tag-exploit","tag-medium","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=66745\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps\/sim\/lib\/core\/security\/deployment.ts of the component...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=66745\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-28T19:38:07+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510\",\"datePublished\":\"2026-06-28T19:38:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745\"},\"wordCount\":434,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-6.3\",\"exploit\",\"MEDIUM\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=66745#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745\",\"name\":\"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-28T19:38:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=66745\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=66745#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=66745","og_locale":"en_US","og_type":"article","og_title":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps\/sim\/lib\/core\/security\/deployment.ts of the component...","og_url":"https:\/\/zero.redgem.net\/?p=66745","og_site_name":"zero redgem","article_published_time":"2026-06-28T19:38:07+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=66745#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=66745"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510","datePublished":"2026-06-28T19:38:07+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=66745"},"wordCount":434,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-6.3","exploit","MEDIUM","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=66745#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=66745","url":"https:\/\/zero.redgem.net\/?p=66745","name":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-28T19:38:07+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=66745#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=66745"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=66745#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"SimStudioAI sim Password Protection deployment.ts weak hash_CVE-2026-13510"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/66745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=66745"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/66745\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=66745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=66745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=66745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}