CVE-2026-3431 is a critical vulnerability affecting SimStudio versions below 0.5.74, where unauthenticated MongoDB tool endpoints allow arbitrary connection parameters. This enables attackers to connect to any reachable MongoDB instance and perform unauthorized data operations, including reading, modifying, and deleting. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without authentication, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.74CPE matchmatch criteria | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion
Mar 2, 2026