5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
Basic Information
ID
CVE-2025-55178
Source
Meta
Published
Sep 24, 2025 at 18:31
Modified
Sep 24, 2025 at 18:50
Affected Product
Vendor
Meta Platforms, Inc
Product
Llama Stack
Version
0.0.0
Affected Versions
Meta Platforms, Inc Llama Stack 0.0.0