CVE-2025-6101

A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated code. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

16 Jun 2025, 12:32

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad crítica en letta-ai letta (hasta la versión 0.4.1). La función function_message del archivo letta/letta/interface.py está afectada. La manipulación del argumento function_name/function_args provoca la neutralización incorrecta de directivas en código evaluado dinámicamente. Se ha hecho público el exploit y puede que sea utilizado.

16 Jun 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 03:15

Updated : 2025-06-16 12:32


NVD link : CVE-2025-6101

Mitre link : CVE-2025-6101

CVE.ORG link : CVE-2025-6101


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')