Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Meta

Published:

Updated: 2025-09-24T18:50:01.680Z

Reserved: 2025-08-08T18:21:47.119Z

Link: CVE-2025-55178

cve-icon Vulnrichment

Updated: 2025-09-24T18:49:44.747Z

cve-icon NVD

Status : Received

Published: 2025-09-24T19:15:36.467

Modified: 2025-09-24T19:15:36.467

Link: CVE-2025-55178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.