PT-2025-39321 · Unknown · Llama Stack

CVE-2025-55178

·

Published

2025-09-24

·

Updated

2026-07-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Llama Stack versions prior to 0.2.20
Description The software accepts unverified parameters in the resolve ast by type function, which may allow for remote code execution.
Recommendations Update to version 0.2.20 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55178
GHSA-X75H-M6JJ-6CJ2
PYSEC-2026-1571

Affected Products

Llama Stack