CVE-2025-9805 is a Server-Side Request Forgery (SSRF) vulnerability in SimStudioAI sim, specifically affecting the processing of files within apps/sim/app/api/proxy/image/route.ts, up to version 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This critical flaw, rated 7.5 HIGH on the CVSS scale, allows unauthenticated remote attackers to potentially access internal resources or conduct further attacks, with a high impact on confidentiality. While a public exploit exists and a patch (3424a338b763115f0269b209e777608e4cd31785) is available, there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.40CPE matchmatch criteria | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.