CVE-2026-108115

Source
https://cve.org/CVERecord?id=CVE-2026-108115
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108115.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-108115
Published
2026-10-10T14:15:51Z
Modified
2026-10-11T02:54:28Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses
Details

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108115.json"
}
References

Affected packages

Git / github.com/kortix-ai/suna

Affected ranges

Type
GIT
Repo
https://github.com/kortix-ai/suna
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.10.7"
        },
        {
            "fixed": "0.13.52"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108115.json"