PatchSiren

letta-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM letta-ai CVE published 2026-08-06

CVE-2026-18990

The CVE-2026-18990 vulnerability affects letta-ai LettaBot 0.2.0, specifically the API Status Route in src/api/server.ts. This vulnerability leads to missing authentication, allowing remote attackers to potentially exploit the system. The CVSS score is 5.5, indicating a medium severity level. Security teams should review the official CVE record and assess their exposure to this vulnerability. The vendor, [truncated]