Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolveastby_type function which could potentially allow for remote code execution.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55178.json"