Vulnerabilities
Vulnerable Software
Sim:  >> Sim  >> 0.5.65  Security Vulnerabilities
On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-03-02
On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.
CVSS Score
9.1
EPSS Score
0.001
Published
2026-03-02


Contact Us

Shodan ® - All rights reserved