MEDIUM
simstudioai
CVE published 2026-09-05
CVE-2026-86115
CVE-2026-86115 is a medium-severity vulnerability in Sim before version 0.8.14, allowing authenticated workflow authors to bypass external URL validation by supplying paths starting with /api/ in HTTP blocks. This could potentially lead to unauthorized access to internal-only endpoints. Defenders responsible for Sim deployments should assess exposure and verify the version in use. Workflow authors and adm [truncated]