CVE-2026-25211Low· 3.2▾ TwilightPoC availableLlama Stack exposes secret in initialization log
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 17.6 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
1 GitHub repo
0.2% → 0.2%
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
llama-stack < 0.4.4Upgrade to a patched release:
llama-stack 0.4.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.