Sim Vulnerabilities

Comprehensive security vulnerability database for Sim products

Last updated: Mar 2, 2026
Total CVEs

3

Critical

2

With Exploits

3

Last 30 Days

0

Severity Distribution

Critical2
67%
High0
0%
Medium1
33%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-34329.3

An attacker can steal OAuth access tokens for any user by simply providing their user ID and a provider name, allowing them to access third-party services without needing to log in. This vulnerability affects versions of SimStudio below 0.5.74 and does not require any authentication, making it particularly dangerous.

simsim
Exploit Available
about 1 month agoMar 2, 2026
CVE-2026-34319.8

An attacker can exploit this vulnerability to connect to any accessible MongoDB database and perform unauthorized actions like reading, changing, or deleting data. This is possible because the affected version of SimStudio allows anyone to send connection requests without needing to log in or restrict which hosts can connect.

simsim
Exploit Available
about 1 month agoMar 2, 2026
CVE-2025-100975.3

This vulnerability allows an attacker to inject malicious code into the SimStudioAI application, potentially compromising its functionality. The attack can be executed remotely, meaning the attacker doesn’t need physical access to the system, but it requires the attacker to manipulate specific input in the application.

simsim
Exploit Available
7 months agoSep 8, 2025

About Sim Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Sim products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.