Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108115— Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses

Quick assessment

Affected
kortix-ai suna
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kortix Suna 0.10.7 至 0.13.52 版本之前的所有版本存在服务器端请求伪造(SSRF)漏洞。攻击者可以通过提供嵌入私有 IPv4 目的地的 IPv6 6to4 或 Teredo 地址,绕过 安全检查。拥有 权限的攻击者可以将连接器基地址(connector base_url)、OpenAPI、Postman 或 MCP URL 设置为指向内部服务或云元数据端点,从而读取这些端点的响应内容。

CVSS 4.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
kortix-ai suna 0.10.7< 0.13.52 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108115

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses
Source: CVE Program / CVE List V5
Vulnerability Description
Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kortix-ai suna 0.10.7 ~ 0.13.52 -

II. Public POCs for CVE-2026-108115

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108115

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-108115 (1)

Proof of Concept for CVE-2026-108115 (2)

Vendor Pages for CVE-2026-108115 (1)

Other References for CVE-2026-108115 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108115

No comments yet


Leave a comment