PT-2026-86386 · Sim · Sim
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sim versions prior to 0.8.14
Description
The software incorrectly classifies tool requests as internal by using URL prefix matching without scheme normalization. This flaw allows authenticated workflow authors to bypass Server-Side Request Forgery (SSRF) validation—a vulnerability where an attacker induces a server-side application to make requests to an unintended location—and obtain internal authentication tokens. By providing paths starting with
/api/ in HTTP blocks, an attacker can access internal-only endpoints, such as the POST /api/function/execute endpoint.Recommendations
Update to version 0.8.14 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sim