Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 10:16
Updated : 2026-09-08 19:20
NVD link : CVE-2026-86115
Mitre link : CVE-2026-86115
CVE.ORG link : CVE-2026-86115
JSON object : View
Products Affected
No product.
CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
