Home

Description

A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of the component CRON Secret Handler. The manipulation of the argument INTERNAL_API_SECRET leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is e359dc2946b12ed5e45a0ec9c95ecf91bd18502a. Applying a patch is the recommended action to fix this issue.

PUBLISHED Reserved 2025-12-25 | Published 2025-12-26 | Updated 2025-12-26 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Improper Authentication

Product status

0.5.0
affected

0.5.1
affected

0.5.2
affected

0.5.3
affected

0.5.4
affected

0.5.5
affected

0.5.6
affected

0.5.7
affected

0.5.8
affected

0.5.9
affected

0.5.10
affected

0.5.11
affected

0.5.12
affected

0.5.13
affected

0.5.14
affected

0.5.15
affected

0.5.16
affected

0.5.17
affected

0.5.18
affected

0.5.19
affected

0.5.20
affected

0.5.21
affected

0.5.22
affected

0.5.23
affected

0.5.24
affected

0.5.25
affected

0.5.26
affected

0.5.27
affected

Timeline

2025-12-25:Advisory disclosed
2025-12-25:VulDB entry created
2025-12-25:VulDB entry last update

Credits

28Hus (VulDB User) reporter

References

gist.github.com/H2u8s/c533741e1b36f6245d41cace89a7f4d2 exploit

vuldb.com/?id.338430 (VDB-338430 | simstudioai sim CRON Secret internal.ts improper authentication) vdb-entry technical-description

vuldb.com/?ctiid.338430 (VDB-338430 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.710255 (Submit #710255 | https://github.com/simstudioai https://github.com/simstudioai/sim ≤ v0.5.21 Authentication Bypass by Primary Weakness) third-party-advisory

gist.github.com/H2u8s/c533741e1b36f6245d41cace89a7f4d2 related

github.com/simstudioai/sim/pull/2343 issue-tracking

gist.github.com/H2u8s/c533741e1b36f6245d41cace89a7f4d2 exploit

github.com/...ommit/e359dc2946b12ed5e45a0ec9c95ecf91bd18502a patch

cve.org (CVE-2025-15099)

nvd.nist.gov (CVE-2025-15099)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.