Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-31066 Llama Stack could potentially allow for remote code execution
Github GHSA Github GHSA GHSA-x75h-m6jj-6cj2 Llama Stack could potentially allow for remote code execution
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 30 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
Title llama-stack: llama stack unverified input
Weaknesses CWE-20
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Meta Platforms Inc
Meta Platforms Inc llama Stack
Vendors & Products Meta Platforms Inc
Meta Platforms Inc llama Stack

Wed, 24 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Meta

Published:

Updated: 2025-09-24T18:50:01.680Z

Reserved: 2025-08-08T18:21:47.119Z

Link: CVE-2025-55178

cve-icon Vulnrichment

Updated: 2025-09-24T18:49:44.747Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-24T19:15:36.467

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-55178

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-09-24T18:31:28Z

Links: CVE-2025-55178 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-09-25T08:21:09Z