← Vulnerability feed

Vulnerability record · CVE-2025-7107 · published 7 July 2025

CVE-2025-7107: Sim path traversal vulnerability

Sim · Sim

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

5.5 CVSS 4.0 Medium EPSS 0.79% · top 45.7% CWE-22 · Path traversal
5.5CVSS 4.0 base score, v2 5.0
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/simstudioai/sim/commit/b2450530d1ddd0397a11001a72aa0fde401db16a Patch
https://github.com/simstudioai/sim/pull/437 ExploitPatch
https://github.com/vri-report/reports/issues/2 ExploitIssue TrackingThird Party Advisory
https://github.com/vri-report/reports/issues/2#issue-3161840085 ExploitIssue TrackingRelease NotesThird Party Advisory
https://vuldb.com/?ctiid.315018 Permissions RequiredVDB Entry
https://vuldb.com/?id.315018 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.601043 Third Party AdvisoryVDB Entry
https://github.com/vri-report/reports/issues/2 ExploitIssue TrackingThird Party Advisory

Track CVE-2025-7107 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-3431Sim missing authorization vulnerabilityOn SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos…EPSS 0.61%9.3CVE-2026-3432Sim missing authorization vulnerabilityOn SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided …EPSS 0.45%5.5CVE-2025-15099Sim improper authentication vulnerabilityA vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of …EPSS 0.79%5.5CVE-2025-7114Sim improper authentication vulnerabilityA vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne…EPSS 0.52%5.3CVE-2025-10097Sim injection vulnerabilityA vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.t…EPSS 0.76%2.1CVE-2025-10096Sim server-side request forgery (ssrf) vulnerabilityA vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Ex…EPSS 0.28%2.1CVE-2025-9805Sim server-side request forgery (ssrf) vulnerabilityA vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file a…EPSS 0.29%2.1CVE-2025-9800Sim improper access control vulnerabilityA weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of th…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2025-7107), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.