llama-stack
Open-source, OpenAI-compatible API server with pluggable providers for any model and any infrastructure
Activity
- Latest release
- 1mo ago
- Total releases
- 105
- Cadence
- ~7 days
- Last 12 months
- 27
Details
- License
- MIT
- First release
- Sep 10, 2024
| Version | Released | |
|---|---|---|
0.7.3
patch
| ||
0.4.7
patch
| ||
0.5.4
patch
| ||
0.5.3
patch
| ||
0.4.6
patch
| ||
0.7.2
patch
| ||
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.1
patch
| ||
0.6.0
minor
| ||
0.5.2
patch
| ||
0.5.1
patch
| ||
0.4.5
patch
| ||
0.5.0
minor
| ||
0.5.0rc1
pre
| ||
0.4.4
patch
| ||
0.4.3
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.5
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.4
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.24
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.23
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.22
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.21
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.20
patch
1 CVE
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.19
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.18
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.17
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.16
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.15
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.14
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.13
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.12
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.11
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.10.1
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.10
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.9
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.8
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.7
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.6
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.5
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.4
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.3
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.2
patch
2 CVEs
CVE-2026-25211
PYSEC-2026-1572
GHSA-xmfj-7pp5-fxr6
Jul 07, 2026
Llama Stack exposes secret in initialization log
3.2
/ 10
Low
Local
High
None
None
Changed
Low
None
None
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 77 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.20
0.2.21
0.2.22
0.2.23
0.2.24
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.2
0.4.3
Fixed in
0.4.4
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55178
PYSEC-2026-1571
GHSA-x75h-m6jj-6cj2
Jul 07, 2026
Llama Stack could potentially allow for remote code execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution. Affected versions
0.0.18
0.0.19
0.0.1a0
0.0.1a1
0.0.1a2
0.0.1a3
0.0.1a4
0.0.1a5
0.0.20
0.0.21
0.0.23
0.0.24
+ 62 more Show less
0.0.35
0.0.36
0.0.37
0.0.38
0.0.39
0.0.40
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.51.dev0
0.0.52
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.5.1
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.10
0.2.10.1
0.2.11
0.2.12
0.2.13
0.2.14
0.2.15
0.2.16
0.2.17
0.2.18
0.2.19
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
Fixed in
0.2.20
References
Updated Jul 07, 2026 · Source: OSV.dev |