Junglewise Threat Intelligence

CVE-2026-12811: Kortix-AI Suna XSS in Auth Endpoint returnUrl parameter

CVE-2026-12811 · Severity: medium · CVSS 4.3 · Published 2026-06-21

Executive brief

Kortix-AI Suna, an AI command center platform, contains a security vulnerability in its authentication pages. An attacker can create a malicious link that, if clicked by a user, executes unauthorized scripts in that user's browser. This could allow an attacker to steal login sessions, access sensitive data, or perform actions on behalf of the victim.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the /auth and /auth/password pages of Kortix-AI Suna. The application improperly handles the 'returnUrl' and 'redirect' query parameters, passing them directly to Next.js router functions (router.replace and router.push). Because these functions eventually update window.location, an attacker can use the 'javascript:' protocol to execute arbitrary code in the victim's browser context. This can lead to session hijacking via cookie theft or unauthorized API requests. The issue is fixed in version 0.8.39 by implementing input validation that ensures redirect paths are relative and do not use unsafe protocols.

Affected products

  • kortix-ai suna up to 0.8.38

Timeline

  • 2026-04-10: disclosed: Vulnerability reported to vendor by researcher TrebledJ
  • 2026-04-13: patched: Fix committed to main branch
  • 2026-06-21: advisory: CVE-2026-12811 published

References

Related threats