Executive brief
SimStudioAI is an open-source platform for building AI-powered applications. A code injection vulnerability in the function execution API endpoint allows attackers to submit arbitrary JavaScript code that is executed on the server without proper validation. An attacker can remotely execute arbitrary code and gain full system access, posing a severe operational risk.
Technical details
The vulnerability exists in the POST endpoint `/api/function/execute` in the route.ts file, where the `code` parameter from the request body is directly embedded into a Node.js Script context without sanitization, validation, or filtering (CWE-74, CWE-94). The vulnerable code concatenates user-supplied input into a JavaScript string that is then executed via the `script.runInContext()` method. The attack is network-accessible and requires no authentication; an attacker can craft a POST request with malicious JavaScript code in the `code` parameter to execute arbitrary Node.js code, including spawning child processes and executing system commands. A proof-of-concept demonstrates executing arbitrary shell commands with full process privileges. The vulnerability was patched in pull request #1149.
Affected products
- SimStudioAI sim 0.1.19 and prior
Timeline
- 2025-09-08: disclosed: Vulnerability published in GHSA-g4c9-f287-64xg
- 2025-08-14: other: RCE vulnerability discovered and reported as issue #961
- 2025-09-15: patched: Fix available in pull request #1149