CNNVD-202506-1854 Information

CNNVD ID

CNNVD-202506-1854

CVE-2025-6101

  • CNNVD Published: 2025-06-16

Description (Chinese)

Letta-ai letta是Letta-ai开源的一个具有内存、推理和上下文管理的有状态代理框架。 letta-ai letta 0.4.1及之前版本存在安全漏洞,该漏洞源于动态代码评估不当问题,可能导致执行任意代码。

Description (English)

Letta-ai letta is a state-of-the-art proxy framework, managed by memory, reasoning and context, from the open source of Letta-ai. There is a security loophole in the letta-ai letta 0.4.1 and earlier versions, which stems from inappropriate assessments of dynamic codes, which may lead to the implementation of arbitrary codes.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Letta-ai

Published

2025-06-16

Last Modified

2026-02-24

References

https://vuldb.com/?id.312570 https://vuldb.com/?submit.590528 https://github.com/letta-ai/letta/issues/2613 https://vuldb.com/?ctiid.312570 https://access.redhat.com/security/cve/cve-2025-6101

Patch

https://github.com/letta-ai/letta/releases

Share on: