CVE-2025-7107

Source
https://cve.org/CVERecord?id=CVE-2025-7107
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7107.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-7107
Published
2025-07-07T02:02:07.997Z
Modified
2026-08-12T03:51:36.794520286Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
SimStudioAI sim route.ts handleLocalFile path traversal
Details

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as b2450530d1ddd0397a11001a72aa0fde401db16a. It is recommended to apply a patch to fix this issue.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.1.0"
                },
                {
                    "last_affected": "0.1.0"
                },
                {
                    "introduced": "0.1.3"
                },
                {
                    "last_affected": "0.1.3"
                },
                {
                    "introduced": "0.1.4"
                },
                {
                    "last_affected": "0.1.4"
                },
                {
                    "introduced": "0.1.5"
                },
                {
                    "last_affected": "0.1.5"
                },
                {
                    "introduced": "0.1.6"
                },
                {
                    "last_affected": "0.1.6"
                },
                {
                    "introduced": "0.1.7"
                },
                {
                    "last_affected": "0.1.7"
                },
                {
                    "introduced": "0.1.8"
                },
                {
                    "last_affected": "0.1.8"
                },
                {
                    "introduced": "0.1.9"
                },
                {
                    "last_affected": "0.1.9"
                },
                {
                    "introduced": "0.1.10"
                },
                {
                    "last_affected": "0.1.10"
                },
                {
                    "introduced": "0.1.11"
                },
                {
                    "last_affected": "0.1.11"
                },
                {
                    "introduced": "0.1.12"
                },
                {
                    "last_affected": "0.1.12"
                },
                {
                    "introduced": "0.1.13"
                },
                {
                    "last_affected": "0.1.13"
                },
                {
                    "introduced": "0.1.14"
                },
                {
                    "last_affected": "0.1.14"
                },
                {
                    "introduced": "0.1.15"
                },
                {
                    "last_affected": "0.1.15"
                },
                {
                    "introduced": "0.1.16"
                },
                {
                    "last_affected": "0.1.16"
                },
                {
                    "introduced": "0.1.17"
                },
                {
                    "last_affected": "0.1.17"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7107.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/simstudioai/sim

Affected ranges

Type
GIT
Repo
https://github.com/simstudioai/sim
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.1.1"
        },
        {
            "last_affected": "0.1.1"
        },
        {
            "introduced": "0.1.2"
        },
        {
            "last_affected": "0.1.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.1
0.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7107.json"