CVE-2026-25211
LOW 3.2EPSS 0.2%
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
- CVSS v3.1
- 3.2 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N - CVSS v3.1
- 3.2 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N - EPSS
- 0.22% chance of exploitation in the next 30 days, 13th percentile
- Published
- 2026-01-30
- Updated
- 2026-02-03
Proof-of-concept exploits (1)
- mbanyamer/Llama-Stack-0.4.0rc3-local-CVE-2026-252110★ · 2026-01-31