{"id":"CVE-2026-86115","summary":"Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ Path","details":"Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.","modified":"2026-09-10T03:30:19.788343069Z","published":"2026-09-05T09:59:06.026Z","database_specific":{"cwe_ids":["CWE-441"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86115.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86115.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86115"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sim-before-0.8.14-confused-deputy-in-tool-url-routing-mints-an-internal-token-for-a-user-supplied-api-path"},{"type":"FIX","url":"https://github.com/simstudioai/sim/pull/7179"},{"type":"PACKAGE","url":"https://github.com/simstudioai/sim"},{"type":"ARTICLE","url":"https://github.com/geo-chen/oss/blob/main/sim.md"},{"type":"ARTICLE","url":"https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/lib/auth/hybrid.ts"},{"type":"ARTICLE","url":"https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/tools/index.ts"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simstudioai/sim","events":[{"introduced":"0"},{"fixed":"d59b02c95b0476d3128e52ff196ac5325dfae8af"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"fixed":"0.8.14"}]}}],"versions":["v0.8.13","v0.8.12","v0.8.11","typescript-sdk-v0.2.0","v0.8.10","v0.8.9","v0.8.8","v0.8.7","v0.8.6","v0.8.5","v0.8.4","v0.8.3","v0.8.2","v0.8.1","v0.8.0","python-sdk-v0.2.0","v0.7.68","v0.7.67","v0.7.66","v0.7.65","v0.7.64","v0.7.62","v0.7.61","v0.7.60","v0.7.59","v0.7.58","v0.7.57","v0.7.56","v0.7.55","v0.7.54","v0.7.53","v0.7.52","v0.7.51","v0.7.50","v0.7.49","v0.7.48","v0.7.47","v0.7.46","v0.7.44","v0.7.43","v0.7.41","v0.7.40","v0.7.39","v0.7.38","v0.7.37","v0.7.36","v0.7.35","v0.7.34","v0.7.33","v0.7.32","v0.7.31","v0.7.30","v0.7.29","v0.7.27","v0.7.26","v0.7.25","v0.7.24","v0.7.23","v0.7.22","v0.7.21","v0.7.20","v0.7.19","v0.7.18","v0.7.17","v0.7.16","v0.7.15","v0.7.14","v0.7.13","v0.7.12","v0.7.11","v0.7.10","v0.7.9","v0.7.8","v0.7.7","v0.7.6","v0.7.5","v0.7.4","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.103","v0.6.102","v0.6.101","v0.6.100","v0.6.99","v0.6.98","v0.6.97","v0.6.96","v0.6.95","v0.6.94","v0.6.93","v0.6.92","v0.6.91","v0.6.90","v0.6.89","v0.6.88","v0.6.87","v0.6.86","v0.6.85","v0.6.84","v0.6.83","v0.6.82","v0.6.81","v0.6.80","v0.6.79","v0.6.78","v0.6.77","v0.6.76","v0.6.75","v0.6.73","v0.6.72","v0.6.71","v0.6.69","v0.6.68","v0.6.67","v0.6.66","v0.6.65","v0.6.64","v0.6.63","v0.6.62","v0.6.61","v0.6.60","v0.6.59","v0.6.58","v0.6.56","v0.6.55","v0.6.54","v0.6.53","v0.6.52","v0.6.51","v0.6.50","v0.6.49","v0.6.48","v0.6.47","v0.6.46","v0.6.45","v0.6.44","v0.6.43","v0.6.42","v0.6.41","v0.6.40","v0.6.39","v0.6.38","v0.6.37","v0.6.36","v0.6.35","v0.6.34","v0.6.33","v0.6.32","v0.6.31","v0.6.30","v0.6.29","v0.6.28","v0.6.27","v0.6.26","v0.6.25","v0.6.24","v0.6.23","v0.6.22","v0.6.21","v0.6.20","v0.6.19","v0.6.18","v0.6.17","v0.6.16","v0.6.15","v0.6.14","v0.6.13","v0.6.12","v0.6.11","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.5.113","v0.5.112","v0.5.111","v0.5.110","v0.5.109","v0.5.108","v0.5.107","v0.5.106","v0.5.105","v0.5.104","v0.5.103","v0.5.102","v0.5.101","v0.5.100","v0.5.99","v0.5.98","v0.5.97","v0.5.96","v0.5.95","v0.5.94","v0.5.93","v0.5.92","v0.5.91","v0.5.89","v0.5.88","v0.5.87","v0.5.86","v0.5.85","v0.5.84","v0.5.83","v0.5.82","v0.5.81","v0.5.80","v0.5.79","v0.5.78","v0.5.77","v0.5.76","v0.5.75","v0.5.74","v0.5.73","v0.5.72","v0.5.71","typescript-sdk-v0.1.2","python-sdk-v0.1.2","v0.5.70","v0.5.68","v0.5.67","v0.5.66","v0.5.65","v0.5.64","v0.5.63","v0.5.62","v0.5.61","v0.5.60","v0.5.59","v0.5.58","v0.5.57","v0.5.56","v0.5.55","v0.5.54","v0.5.53","v0.5.52","v0.5.51","v0.5.50","v0.5.49","v0.5.48","v0.5.47","v0.5.46","v0.5.45","v0.5.44","v0.5.43","v0.5.42","v0.5.41","v0.5.40","v0.5.39","v0.5.38","v0.5.37","v0.5.36","v0.5.35","v0.5.34","v0.5.33","v0.5.32","v0.5.31","v0.5.30","v0.5.29","v0.5.28","v0.5.27","v0.5.26","v0.5.25","v0.5.24","v0.5.23","v0.5.22","v0.5.21","v0.5.20","v0.5.19","v0.5.18","v0.5.17","v0.5.16","v0.5.15","v0.5.14","v0.5.13","typescript-sdk-v0.1.1","python-sdk-v0.1.1","v0.5.12","v0.5.11","v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.2","v0.5.1","v0.5","v0.4.11","v0.4.10","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.58","v0.3.57","v0.3.56","v0.3.55","v0.3.54","v0.3.53","v0.3.52","v0.3.51","v0.3.50","v0.3.47","v0.3.46","v0.3.45","v0.3.44","v0.3.43","v0.3.42","v0.3.41","v0.3.40","v0.3.39","v0.3.38","v0.3.37","v0.3.36","v0.3.35","v0.3.34","v0.3.33","v0.3.32","v0.3.31","v0.3.30","v0.3.28","v0.3.27","v0.3.26","v0.3.24","v0.3.23","v0.3.22","v0.3.21","v0.3.19","v0.2.7","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86115.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}]}