A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of the component CRON Secret Handler. The manipulation of the argument INTERNAL_API_SECRET leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is e359dc2946b12ed5e45a0ec9c95ecf91bd18502a. Applying a patch is the recommended action to fix this issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Sim
Sim sim
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:*
Vendors & Products Sim
Sim sim

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Simstudioai
Simstudioai sim
Vendors & Products Simstudioai
Simstudioai sim

Fri, 26 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Dec 2025 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps/sim/lib/auth/internal.ts of the component CRON Secret Handler. The manipulation of the argument INTERNAL_API_SECRET leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is e359dc2946b12ed5e45a0ec9c95ecf91bd18502a. Applying a patch is the recommended action to fix this issue.
Title simstudioai sim CRON Secret internal.ts improper authentication
Weaknesses CWE-287
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-26T15:04:35.405Z

Reserved: 2025-12-25T16:18:38.982Z

Link: CVE-2025-15099

cve-icon Vulnrichment

Updated: 2025-12-26T15:03:02.783Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-26T04:15:40.347

Modified: 2026-01-08T22:00:26.910

Link: CVE-2025-15099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-29T22:33:33Z

Weaknesses