CVE-2026-4965

Source
https://cve.org/CVERecord?id=CVE-2026-4965
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4965.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-4965
Published
2026-03-27T17:41:46.743Z
Modified
2026-07-15T01:49:08.662653544Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection
Details

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolvetype of the file letta/functions/astparsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically evaluated code. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-94",
        "CWE-95"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4965.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.16.4"
                },
                {
                    "last_affected": "0.16.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/letta-ai/letta

Affected ranges

Type
GIT
Repo
https://github.com/letta-ai/letta
Events
Database specific
{
    "cpe": "cpe:2.3:a:letta:letta:0.16.4:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.16.4"
        },
        {
            "last_affected": "0.16.4"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

0.*
0.16.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4965.json"