Internal Authentication Token Bypass in Sim by SimStudioAI
CVE-2026-86115

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86115?

An authentication flaw in Sim versions prior to 0.8.14 allows authenticated workflow authors to exploit URL routing misconfigurations. Specifically, the system erroneously classifies tool requests as internal based on URL prefix matching without adequately normalizing the scheme. This oversight lets attackers bypass external URL validation, enabling them to interact with sensitive internal-only endpoints by constructing requests that start with '/api/' in HTTP blocks. This vulnerability illustrates a potential for unauthorized access to critical functionalities, compromising system integrity.

Affected Version(s)

sim 0 < 0.8.14

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.