Letta is an AI agent framework and runtime that allows dynamic code execution and multi-turn conversation management, presenting an attack surface centered on code generation and external request handling. Its observed vulnerability profile centers on code-injection and eval-injection flaws alongside server-side request forgery, reflecting the inherent risks of evaluating dynamically constructed code and the framework's integration with external services and model APIs. Current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Letta over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51482HIGH Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system co | Jul 22, 2025 | 8.8 | 40 | NO | YES |
CVE-2026-4965CRITICAL A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2 | Mar 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-4964MEDIUM A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_he | Mar 27, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Letta.
Media articles that mention a CVE ID that affects a product developed by Letta — matched by CVE ID, not by vendor name.