VYPR

Suna

by Kortix AI

CVEs (2)

  • CVE-2026-66027Jul 24, 2026
    risk 0.00cvss epss 0.00

    Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read…

  • CVE-2026-12811Jun 21, 2026
    risk 0.00cvss epss 0.01

    A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross…