Llama StackGHSA-xmfj-7pp5-fxr6
Llama Stack exposes secret in initialization log
Low3.2CVE-2026-25211 · Published Jan 30, 2026 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-stack PyPI | < 0.4.4 | 0.4.4 |
Details and references
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- CVE-2026-25211, PYSEC-2026-1572
More Llama Stack advisories
All Llama Stack| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 242025 | Llama Stack could potentially allow for remote code execution CVE-2025-55178Medium5.3fixed in 0.2.20 | Medium5.3 | 0.2.20 |