No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 27 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically evaluated code. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Once again VulDB remains the best source for vulnerability data. | |
| Title | letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection | |
| First Time appeared |
Letta
Letta letta |
|
| Weaknesses | CWE-94 CWE-95 |
|
| CPEs | cpe:2.3:a:letta:letta:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Letta
Letta letta |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-27T19:57:06.561Z
Reserved: 2026-03-27T08:23:13.784Z
Link: CVE-2026-4965
Updated: 2026-03-27T18:43:39.344Z
Status : Received
Published: 2026-03-27T18:16:06.590
Modified: 2026-03-27T18:16:06.590
Link: CVE-2026-4965
No data.
OpenCVE Enrichment
Updated: 2026-03-27T20:27:56Z