Medium severity6.3NVD Advisory· Published Sep 8, 2025· Updated Jun 17, 2026
CVE-2025-10097
CVE-2025-10097
Description
A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of the argument code leads to code injection. The attack is possible to be carried out remotely.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simstudionpm | <= 0.1.19 | — |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/simstudioai/sim/issues/961nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/simstudioai/sim/issues/961nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-g4c9-f287-64xgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-10097ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- github.com/simstudioai/sim/pull/1149/commits/3f790867427275ebae3b3dc75cf1d93d912ac9caghsaWEB
- vuldb.comnvdPermissions RequiredVDB EntryWEB
News mentions
0No linked articles in our index yet.