Suna message queue API broken access control vulnerability
Suna before version 0.9.102 contains a broken access control vulnerability in its message queue API that allows authenticated attackers to access queue resources belonging to other users, read their prompt queues, and inject malicious prompts into their AI agent sessions.
Disclosed 24 July 2026 · Record updated 13 September 2026
Impact
Authenticated attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing malicious messages to be forwarded to victims' running AI agents with the victims' credentials and permissions.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-66027
