PT-2026-64372 · Suna · Suna
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Suna versions prior to 0.9.102
Description
Broken access control in the message queue API allows authenticated attackers to access and manipulate queue resources of other users due to missing ownership and account isolation checks. This allows attackers to read pending prompt queues for all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue. Consequently, the background drainer may forward malicious messages to the victim's active AI agent using the victim's credentials and permissions.
Recommendations
Update Suna to version 0.9.102 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suna