Skip to content
Llama StackGHSA-xmfj-7pp5-fxr6

Llama Stack exposes secret in initialization log

Low3.2CVE-2026-25211 · Published Jan 30, 2026 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-stack
PyPI
< 0.4.40.4.4
Details and references

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
CVE-2026-25211, PYSEC-2026-1572

More Llama Stack advisories

All Llama Stack
DateAdvisory
Sep 242025Llama Stack could potentially allow for remote code execution
CVE-2025-55178Medium5.3fixed in 0.2.20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.