LOW3.2
PYSEC-2026-1572
Llama Stack exposes secret in initialization log
Quick fix
PYSEC-2026-1572 — llama-stack: upgrade to the fixed version with the command below.
pip install --upgrade 'llama-stack>=0.4.4'Details
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-25211[ADVISORY]
- https://github.com/llamastack/llama-stack/commit/b709bd77b6c1fad68a30a4888baa6f2337eaef6f[WEB]
- https://github.com/llamastack/llama-stack[PACKAGE]
- https://github.com/llamastack/llama-stack/compare/v0.4.0rc2...v0.4.0rc3[WEB]
- https://pypi.org/project/llama-stack[PACKAGE]
- https://github.com/advisories/GHSA-xmfj-7pp5-fxr6[ADVISORY]