Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 30 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
Title llamastack/llama-stack: Sensitive Information Exposure Through Log Files in Llama Stack PGVector Integration
References
Metrics threat_severity

None

threat_severity

Low


Fri, 30 Jan 2026 07:30:00 +0000

Type Values Removed Values Added
Description Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-30T07:22:14.986Z

Reserved: 2026-01-30T07:16:14.082Z

Link: CVE-2026-25211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-30T08:16:02.563

Modified: 2026-01-30T08:16:02.563

Link: CVE-2026-25211

cve-icon Redhat

Severity : Low

Publid Date: 2026-01-07T12:15:22Z

Links: CVE-2026-25211 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses