CVE Feed

    Dashboard / CVE / CVE-2025-7107

    CVE-2025-7107

    A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

    Published:Jul 7, 2025
    Last Modified:Oct 1, 2025
    EPS:Jul 7, 2025
    EPSS Score:0.00073
    CVSS Score:5.3

    Affected Products

    Vendor
    Sim
    Product
    Sim
    Vendor
    Simstudioai
    Product
    Sim

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High