Internal Authentication Token Bypass in Sim by SimStudioAI
CVE-2026-86115
5.3MEDIUM
What is CVE-2026-86115?
An authentication flaw in Sim versions prior to 0.8.14 allows authenticated workflow authors to exploit URL routing misconfigurations. Specifically, the system erroneously classifies tool requests as internal based on URL prefix matching without adequately normalizing the scheme. This oversight lets attackers bypass external URL validation, enabling them to interact with sensitive internal-only endpoints by constructing requests that start with '/api/' in HTTP blocks. This vulnerability illustrates a potential for unauthorized access to critical functionalities, compromising system integrity.
Affected Version(s)
sim 0 < 0.8.14
