Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10096

Опубликовано: 08 сент. 2025
Источник: nvd
CVSS3: 6.3
CVSS3: 6.5
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of the argument filePath can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 3424a338b763115f0269b209e777608e4cd31785. Applying a patch is advised to resolve this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:*
Версия до 0.3.40 (исключая)

EPSS

Процентиль: 13%
0.00042
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
github
5 месяцев назад

A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of the argument filePath can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 3424a338b763115f0269b209e777608e4cd31785. Applying a patch is advised to resolve this issue.

EPSS

Процентиль: 13%
0.00042
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-918