CVE-2025-51482
HIGH EXPLOITED NUCLEILetta <0.7.12 - RCE
Title source: llmDescription
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.
Exploits (1)
Nuclei Templates (1)
Letta Letta 0.7.12 - Remote Code Execution
HIGHVERIFIEDby RaghavArora14
FOFA:
title="Letta"
Scores
CVSS v3
8.8
EPSS
0.0579
EPSS Percentile
90.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-10-24
CWE
CWE-94
Status
published
Products (1)
letta/letta
0.7.12
Published
Jul 22, 2025
Tracked Since
Feb 18, 2026