CVE-2025-6101

MEDIUM

Letta-ai <0.4.1 - Improper Neutralization

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated code. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 31.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-94 CWE-95
Status published
Products (2)
letta-ai/letta 0.4.0
letta-ai/letta 0.4.1
Published Jun 16, 2025
Tracked Since Feb 18, 2026