CVE-2026-12811Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.8.39 can resolve this issue. This patch is called f5dec7aa0c1b8fa0125938f292c0f2430ca75f6c. It is advisable to upgrade the affected component. The researcher explains: "The issue was fixed in v0.8.39 without notifying the wider user base via a security disclosure."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-21: 2Mentions · 2026-06-22: 1Technical Details · 2026-06-21: 2Technical Details · 2026-06-22: 106-2106-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-212
Disclosure2
2026-06-221
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12811 Cross-Site Scripting in Kortix-AI Suna Up to 0.8.38 Auth Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12811

    Post summary

    The entry reports a new XSS vulnerability in the authentication endpoint of Kortix‑AI Suna up to version 0.8.38, with no evidence of exploitation, PoC, or patch details.

    00000121
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12811 A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/aut… https://www.cve.org/CVERecord?id=CVE-2026-12811 ----- Traducción: CVE-2026-12811 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-12811, identifying a weakness in the router functions of kortix-ai suna, but provides no PoC, exploit, or remediation details.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12811 A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/aut… https://www.cve.org/CVERecord?id=CVE-2026-12811

    Post summary

    A weakness has been identified in kortix‑ai suna version 0.8.38 and earlier, impacting the router.replace/router.push functions. No details on exploitation, patches, or PoC code are provided.

    00000761
    57.7K followersView on X

Explore more