Vulnerability Description
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Letta | Letta | 0.7.12 |
Related Weaknesses (CWE)
References
- https://github.com/letta-ai/lettaProduct
- https://github.com/letta-ai/letta/pull/2630ExploitIssue TrackingPatch
- https://www.gecko.security/blog/cve-2025-51482ExploitThird Party Advisory
FAQ
What is CVE-2025-51482?
CVE-2025-51482 is a vulnerability with a CVSS score of 8.8 (HIGH). Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted p...
How severe is CVE-2025-51482?
CVE-2025-51482 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-51482?
Check the references section above for vendor advisories and patch information. Affected products include: Letta Letta.