Suna Message Queue Broken Access Control Leading to Cross-User Prompt Injection
highAgentPrompt InjectionSuna versions before 0.9.102 fail to enforce ownership checks on the message queue API, letting any authenticated user read, delete, or inject messages into other users' prompt queues. This allows an attacker to inject arbitrary prompts that are forwarded by the background drainer to a victim's running AI agent, executed with the victim's own credentials and permissions.
Updated Jul 24, 2026 · CVSS 8.3