Vulnerability  ·  2026-10-11

Kortix Suna SSRF guard bypass via IPv6 6to4/Teredo addresses → internal services and metadata (CVSS 4.9)

VulnerabilityMedium impactGlobalCVE-2026-108115
Verified via NVD REST API (published 2026-10-10, VulnCheck). Authenticated SSRF with guard bypass in an AI agent platform.
Connector URLs (including MCP/OpenAPI endpoints) are how agents reach the outside world; a SSRF guard bypass lets a low-privilege project manager pivot into internal networks from the agent host.
The isPrivateIp guard checks only the literal address; IPv6 6to4/Teredo addresses embedding private IPv4 destinations evade it, letting a project manager point connector base_url/OpenAPI/Postman/MCP URLs at internal services and cloud metadata (CWE-918).
kortix-ai/suna 0.10.7 before 0.13.52
Upgrade to 0.13.52 (fix commit 9c949e4d876cd5acf7b23b0a9ee49ca5c53f1332); decode embedded IPv4 for 6to4/Teredo before allowlisting. See VulnCheck advisory.
NVD CVE-2026-108115NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →