CVE-2026-108115
MEDIUM
NVD
CVSS Score
4.9
Severity
MEDIUM
Published
Oct 10, 2026
Vendor
unknown
Description
Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.
References
- https://github.com/kortix-ai/suna
- https://github.com/kortix-ai/suna/blob/v0.13.45/apps/api/src/shared/ssrf-guard.ts#L98-L113
- https://github.com/kortix-ai/suna/commit/9c949e4d876cd5acf7b23b0a9ee49ca5c53f1332
- https://github.com/kortix-ai/suna/releases/tag/v0.13.52
- https://hackmd.io/@haind/suna-ssrf-6to4-guard-bypass