Letta 0.7.12 is vulnerable to remote code execution via POST /v1/tools/run in letta.server.rest_api.routers.v1.tools.run_tool_from_source, allowing attackers to execute arbitrary Python and OS commands via crafted tool source code.
id: CVE-2025-51482
info:
name: Letta Letta 0.7.12 - Remote Code Execution
author: RaghavArora14
...