THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86115 (MEDIUM 5.0) — Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting wit

[NVD] CVE-2026-86115 (MEDIUM 5.0) — Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting wit

mednvdPublished 2026-09-05

CVE-2026-86115 CVSS: 5.0 MEDIUM Published: 2026-09-05T10:16:42.567

Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86115