What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). Authenticated SSRF with guard bypass in an AI agent platform.
Why it matters
Connector URLs (including MCP/OpenAPI endpoints) are how agents reach the outside world; a SSRF guard bypass lets a low-privilege project manager pivot into internal networks from the agent host.
Attack vector
The isPrivateIp guard checks only the literal address; IPv6 6to4/Teredo addresses embedding private IPv4 destinations evade it, letting a project manager point connector base_url/OpenAPI/Postman/MCP URLs at internal services and cloud metadata (CWE-918).
Affected systems
kortix-ai/suna 0.10.7 before 0.13.52
Mitigation
Upgrade to 0.13.52 (fix commit 9c949e4d876cd5acf7b23b0a9ee49ca5c53f1332); decode embedded IPv4 for 6to4/Teredo before allowlisting. See VulnCheck advisory.