CVE-2026-86115 | simstudioai Sim up to 0.8.13 URL Prefix Matching /api/function/execute server-side request forgery

SecurityVulns

A vulnerability was found in simstudioai Sim up to 0.8.13 and classified as critical. This impacts an unknown function of the file /api/function/execute of the component URL Prefix Matching. Executing a manipulation can lead to server-side request forgery.

This vulnerability appears as CVE-2026-86115. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More