CVE-2026-25211: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25211 is a credential exposure vulnerability in Llama Stack (llama-stack) where the pgvector database password is logged in plain text during initialization. It affects all versions of llama-stack before 0.4.0rc3 (pip package affected versions listed as < 0.4.4). The vulnerability was published on January 30, 2026, with the fix merged on January 5, 2026 via PR #4439. It carries a CVSS v3.1 base score of 3.2 (Low) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File): during PGVector adapter initialization, Llama Stack logs the full configuration object — including the plaintext password field — to the application log without any masking or redirection. The fix introduced a safe_config dictionary that replaces the password value with '******' before logging. Exploitation requires local access to the log files, and attack complexity is rated High due to the need to access system logs. A proof-of-concept is publicly available on GitHub (GitHub Advisory, PR #4439).

Example of the vulnerable log output:

vector_io::pgvector: Initializing PGVector memory adapter with config: host='vector-io-pgvector-service' port=5432 db='pgvector' user='pgvector_user' password='realpassword'

Impact

An attacker with local read access to Llama Stack application logs can extract the pgvector database password in plain text, potentially enabling unauthorized access to the connected PostgreSQL/pgvector database. This could lead to theft or manipulation of vector store data (e.g., embeddings, AI model data), and may facilitate lateral movement within the infrastructure if the database credential is reused elsewhere. Availability and integrity of the Llama Stack application itself are not directly impacted by this vulnerability (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available on GitHub at https://github.com/mbanyamer/Llama-Stack-0.4.0rc3-local-CVE-2026-25211, added on March 2, 2026. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.004–0.006%, indicating a very low probability of exploitation in the near term. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, GitHub Advisory).

Exploitation steps

  1. Gain local access: Obtain local access to the system running Llama Stack, either through a legitimate user account, a compromised service account, or another vulnerability enabling local code execution.
  2. Locate log files: Identify the Llama Stack application log files (e.g., by checking default log paths or environment configuration). The relevant logger is llama_stack.providers.remote.vector_io.pgvector.pgvector.
  3. Search for credentials: Grep or search the log files for the initialization message pattern, e.g.:
grep 'password=' /path/to/llama_stack.log
  1. Extract the password: The log line will contain the pgvector password in plain text, e.g., password='realpassword'.
  2. Access the database: Use the extracted credentials to connect directly to the pgvector/PostgreSQL database (host, port, db, user, and password are all present in the same log line), enabling data exfiltration or manipulation (PR #4439, GitHub Advisory).

Indicators of compromise

  • Logs: Presence of log entries matching the pattern vector_io::pgvector: Initializing PGVector memory adapter with config: containing a password= field with a non-masked value in Llama Stack application logs.
  • File System: Unexpected access or copying of Llama Stack log files by non-administrative users or processes; log files with unusual read timestamps.
  • Network: Unexpected or unauthorized connections to the pgvector/PostgreSQL database (default port 5432) from hosts or accounts not normally associated with Llama Stack operations.
  • Database: Unusual login attempts or successful authentications to the pgvector database using the service account credentials, especially from unexpected source IPs or at unusual times (PR #4439).

Mitigation and workarounds

Upgrade Llama Stack to version 0.4.0rc3 or later (pip package: version 0.4.4 or later) to apply the fix, which masks the pgvector password in initialization logs with '******'. As an immediate workaround, restrict read access to Llama Stack log files to only authorized administrators. Additionally, review existing log files for exposed pgvector credentials and rotate the database password if any vulnerable version was previously deployed. Implement log sanitization and monitoring for unauthorized log access going forward (GitHub Advisory, PR #4439).

Community reactions

The vulnerability was reported and fixed by community contributor Bobbins228 via a pull request to the Llama Stack repository, which was reviewed and merged by maintainer franciscojavierarceo on January 5, 2026. The fix was also backported to the release-0.3.x branch. No significant broader media coverage or notable researcher commentary beyond the GitHub advisory and PoC publication has been identified (PR #4439, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management