
🚨 letta-ai Code Inj CVSS: 9.1 RCE via unsafe Python eval() in letta-ai platform. Malicious inputs trigger code execution in AI processing pipelines, perfect for supply chain attacks. https://nvd.nist.gov/vuln/detail/CVE-2026-4965
Post summary
The tweet announces a new high‑severity CVE (CVE‑2026‑4965) describing an RCE vulnerability in letta‑ai’s use of unsafe Python eval(), with no evidence of active exploitation, PoC, or patch details.


