Vulnerability record · CVE-2025-9805 · published 2 September 2025
CVE-2025-9805: Sim server-side request forgery (ssrf) vulnerability
Sim · Sim
A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 3424a338b763115f0269b209e777608e4cd31785. Applying a patch is advised to resolve this issue.
Description
A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 3424a338b763115f0269b209e777608e4cd31785. Applying a patch is advised to resolve this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/simstudioai/sim/commit/3424a338b763115f0269b209e777608e4cd31785 | Patch |
| https://github.com/simstudioai/sim/issues/1128 | ExploitIssue TrackingVendor Advisory |
| https://github.com/simstudioai/sim/issues/1128#issue-3349260976 | ExploitIssue TrackingVendor Advisory |
| https://github.com/simstudioai/sim/issues/1128#issuecomment-3226867869 | Issue TrackingPatch |
| https://vuldb.com/?ctiid.322129 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.322129 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.640821 | Third Party AdvisoryVDB Entry |
Track CVE-2025-9805 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-9805), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.