CVE-2025-9801 is a path traversal vulnerability affecting SimStudioAI sim up to commit ed9b9ad83f1a7c61f4392787fb51837d34eeb0af, stemming from improper handling of the filePath argument. Rated 8.1 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), it allows remote attackers to achieve high integrity and availability impacts with low attack complexity. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available. Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.40CPE matchmatch criteria | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.