---
id: CVE-2024-39025
aliases:
  - GHSA-7p2g-2vxc-5g55
  - PYSEC-2026-1533
title: Letta (previously MemGPT) incorrect access control vulnerability
summary: Letta (previously MemGPT) incorrect access control vulnerability
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: letta
product: letta
ecosystem: pip
affected:
  - letta <= 0.3.17
published: '2024-12-27'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7p2g-2vxc-5g55'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-39025'
  - url: 'https://github.com/letta-ai/letta'
  - url: >-
      https://github.com/letta-ai/letta/blob/0.3.17/memgpt/server/rest_api/admin/users.py#L55-L68
  - url: 'https://github.com/letta-ai/letta/releases/tag/0.3.17'
  - url: >-
      https://medium.com/@cnetsec/a-vulnerability-cve-2024-39025-has-been-identified-in-lettaai-memgpt-v0-3-17-146cb38bb6db
tags:
  - osv
  - pip
epss: 0.00399
epssPercentile: 0.31443
ingestedAt: '2026-07-08T18:25:47.052Z'
---

## Overview

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

## Affected packages

- `letta <= 0.3.17`

## Remediation

Refer to the advisory for the patched release.
