PT-2026-28690 · Letta+1 · Letta

Eric-Z

+1

·

Published

2026-03-27

·

Updated

2026-03-27

·

CVE-2026-4964

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function convert message create to message of the file letta/helpers/message helper.py of the component File URL Handler. Such manipulation of the argument ImageContent leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-4964

Affected Products

Letta