Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Letta

First CVE: Jul 22, 2025Active for: 1 yearTotal CVEs: 3

Letta is an AI agent framework and runtime that allows dynamic code execution and multi-turn conversation management, presenting an attack surface centered on code generation and external request handling. Its observed vulnerability profile centers on code-injection and eval-injection flaws alongside server-side request forgery, reflecting the inherent risks of evaluating dynamically constructed code and the framework's integration with external services and model APIs. Current severity, exploitation activity, and exposure details are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Letta over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2025
12 months ago
Most Recent CVE
Mar 27, 2026
119 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-51482HIGH
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system co
Jul 22, 20258.840NOYES
CVE-2026-4965CRITICAL
A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2
Mar 27, 20269.831NONO
CVE-2026-4964MEDIUM
A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_he
Mar 27, 20266.522NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (66.7%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
33.3% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Letta.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Letta — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Letta's Products

View all 2 CNAs →

Top CWEs