CVE-2025-9800 is an unrestricted file upload vulnerability in SimStudioAI sim, specifically within the HTML File Parser's Import function (apps/sim/app/api/files/upload/route.ts). This flaw allows remote attackers to upload arbitrary files by manipulating the 'File' argument. The vulnerability has a CVSS score of 6.1 (Medium) due to its network-based attack vector, low attack complexity, and potential for limited confidentiality and integrity impacts. While user interaction is required, the attack can lead to server-side compromise. Exploit code for CVE-2025-9800 is publicly available, increasing the risk of exploitation. Despite this, there is currently no evidence of active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.40CPE matchmatch criteria | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.