← volver
CVE-2026-13510

SimStudioAI sim Password Protection deployment.ts weak hash

CVSS 6.3 MEDIUMCWE-327CWE-328
Vexday Risk Score
10Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.3EPSS KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
28 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password Protection Handler. Performing a manipulation results in use of weak hash. The attack is possible to be carried out remotely. The attack's complexity is rated as high. The exploitation appears to be difficult. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
SimStudioAI · sim

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →