
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25211 is a credential exposure vulnerability in Llama Stack (llama-stack) where the pgvector database password is logged in plain text during initialization. It affects all versions of llama-stack before 0.4.0rc3 (pip package affected versions listed as < 0.4.4). The vulnerability was published on January 30, 2026, with the fix merged on January 5, 2026 via PR #4439. It carries a CVSS v3.1 base score of 3.2 (Low) (GitHub Advisory, Feedly).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File): during PGVector adapter initialization, Llama Stack logs the full configuration object — including the plaintext password field — to the application log without any masking or redirection. The fix introduced a safe_config dictionary that replaces the password value with '******' before logging. Exploitation requires local access to the log files, and attack complexity is rated High due to the need to access system logs. A proof-of-concept is publicly available on GitHub (GitHub Advisory, PR #4439).
Example of the vulnerable log output:
vector_io::pgvector: Initializing PGVector memory adapter with config: host='vector-io-pgvector-service' port=5432 db='pgvector' user='pgvector_user' password='realpassword'An attacker with local read access to Llama Stack application logs can extract the pgvector database password in plain text, potentially enabling unauthorized access to the connected PostgreSQL/pgvector database. This could lead to theft or manipulation of vector store data (e.g., embeddings, AI model data), and may facilitate lateral movement within the infrastructure if the database credential is reused elsewhere. Availability and integrity of the Llama Stack application itself are not directly impacted by this vulnerability (GitHub Advisory, Feedly).
A proof-of-concept exploit is publicly available on GitHub at https://github.com/mbanyamer/Llama-Stack-0.4.0rc3-local-CVE-2026-25211, added on March 2, 2026. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.004–0.006%, indicating a very low probability of exploitation in the near term. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, GitHub Advisory).
llama_stack.providers.remote.vector_io.pgvector.pgvector.grep 'password=' /path/to/llama_stack.logpassword='realpassword'.vector_io::pgvector: Initializing PGVector memory adapter with config: containing a password= field with a non-masked value in Llama Stack application logs.Upgrade Llama Stack to version 0.4.0rc3 or later (pip package: version 0.4.4 or later) to apply the fix, which masks the pgvector password in initialization logs with '******'. As an immediate workaround, restrict read access to Llama Stack log files to only authorized administrators. Additionally, review existing log files for exposed pgvector credentials and rotate the database password if any vulnerable version was previously deployed. Implement log sanitization and monitoring for unauthorized log access going forward (GitHub Advisory, PR #4439).
The vulnerability was reported and fixed by community contributor Bobbins228 via a pull request to the Llama Stack repository, which was reviewed and merged by maintainer franciscojavierarceo on January 5, 2026. The fix was also backported to the release-0.3.x branch. No significant broader media coverage or notable researcher commentary beyond the GitHub advisory and PoC publication has been identified (PR #4439, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."