Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
https://www.facebook.com/security/advisories/cve-2025-55178
https://github.com/llamastack/llama-stack/releases/tag/v0.2.20