CVE-2026-4965Disclosure(letta / letta)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically evaluated code. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94CWE-95

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • letta

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
letta

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-28: 3Technical Details · 2026-03-28: 103-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 letta-ai Code Inj CVSS: 9.1 RCE via unsafe Python eval() in letta-ai platform. Malicious inputs trigger code execution in AI processing pipelines, perfect for supply chain attacks. https://nvd.nist.gov/vuln/detail/CVE-2026-4965

    Post summary

    The tweet announces a new high‑severity CVE (CVE‑2026‑4965) describing an RCE vulnerability in letta‑ai’s use of unsafe Python eval(), with no evidence of active exploitation, PoC, or patch details.

    1000029
    434 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-4965 A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomple… https://www.cve.org/CVERecord?id=CVE-2026-4965 ----- Traducción: CVE-2026-4965 Se … http://infoflow.cloud`

    Post summary

    The tweet merely cites CVE-2026-4965 with a brief function reference and a link to the CVE record, lacking any substantive technical or exploit information.

    0000045
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4965 A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomple… https://www.cve.org/CVERecord?id=CVE-2026-4965

    Post summary

    The text reports the detection of CVE-2026-4965 in letta-ai letta 0.16.4, indicating a function-level issue in ast_parsers.py, but it does not provide any PoC, exploit details, mitigation, or evidence of active exploitation.

    00000254
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applettaletta0.16.4--

Explore more