CVE-2025-6101 | letta-ai letta up to 0.4.1 letta/letta/interface.py function_message function_name/function_args eval injection (Issue 2613 / EUVD-2025-18359)
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is traded as CVE-2025-6101. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.