CVE-2025-9800

MEDIUM

Sim < 0.3.40 - Improper Access Control

Title source: rule
STIX 2.1

Description

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of the file apps/sim/app/api/files/upload/route.ts of the component HTML File Parser. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This patch is called 45372aece5e05e04b417442417416a52e90ba174. A patch should be applied to remediate this issue.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.322115
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.322115
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.641129
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://github.com/simstudioai/sim/issues/958
Exploit, Issue Tracking, Vendor Advisory exploit issue-tracking
https://github.com/simstudioai/sim/issues/958#issue-3320696271

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
sim/sim < 0.3.40
Published Sep 01, 2025
Tracked Since Feb 18, 2026