
CVE-2026-25211 Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. https://www.cve.org/CVERecord?id=CVE-2026-25211
Post summary
CVE-2026-25211 concerns Llama Stack’s exposure of pgvector passwords in init logs prior to 0.4.0rc3, with no PoC, exploit or patch details provided in the statement.

