CVE-2025-6101: letta-ai letta interface.py function_message eval injection
Published Jun 16, 2025
·Updated
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function functionmessage of the file letta/letta/interface.py. The manipulation of the argument functionname/functionargs leads to improper neutralization of directives in dynamically evaluated code. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
letta-ai Letta<=0.4.1
Event History
Jun 16, 2025
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Aug 30, 57482
Event
via FIRST·08:09 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6101?
CVE-2025-6101 is classified as critical.
2
How do I fix CVE-2025-6101?
To fix CVE-2025-6101, update the letta-ai letta software to a version higher than 0.4.1.
3
What vulnerabilities are associated with CVE-2025-6101?
CVE-2025-6101 involves improper neutralization of directives in dynamic calls.
4
Which versions of letta-ai letta are affected by CVE-2025-6101?
CVE-2025-6101 affects letta-ai letta versions up to and including 0.4.1.
5
What component of letta-ai letta is vulnerable in CVE-2025-6101?
The vulnerable component in CVE-2025-6101 is the function_message in the file letta/letta/interface.py.