PT-2025-36482 · Unknown · Simstudioai Sim

Zast.Ai

·

Published

2025-09-08

·

Updated

2026-03-10

·

CVE-2025-10097

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SimStudioAI sim versions up to 1.0.0
Description: A vulnerability exists in SimStudioAI sim up to version 1.0.0. The issue involves code injection due to the manipulation of the code argument within an unknown function of the file apps/sim/app/api/function/execute/route.ts. This allows for remote exploitation.
Recommendations: Versions prior to 1.0.0 should be used. As a temporary workaround, consider restricting access to the file apps/sim/app/api/function/execute/route.ts to minimize the risk of exploitation. Avoid using the argument code in the /api/function/execute endpoint until the issue is resolved.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10097
GHSA-G4C9-F287-64XG

Affected Products

Simstudioai Sim