llama-stack vulnerabilities
CVEs whose affected-version data names the llama-stack package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-25211Low· 3.2PoCLlama Stack exposes secret in initialization log
Llama Stack exposes secret in initialization log
▾ Twilightllama-stack · llama-stackEPSS 0.23%via OSV
CVE-2025-55178Medium· 5.3Llama Stack could potentially allow for remote code execution
Llama Stack could potentially allow for remote code execution
▾ Sunlitllama-stack · llama-stackEPSS 0.50%via OSV