High severity7.6NVD Advisory· Published Oct 11, 2026
CVE-2026-108760
CVE-2026-108760
Description
LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.0.34
Patches
Vulnerability mechanics
References
4- github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa396452951377e/cli/cmd/orchestrator/services.gonvd
- github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa396452951377e/server/core/settings.pynvd
- hackmd.io/@haind03/llamafarm-default-all-interface-bind-unauthenticated-apinvd
- www.vulncheck.com/advisories/llamafarm-through-0.0.34-unauthenticated-api-exposed-on-all-interfacesnvd
News mentions
0No linked articles in our index yet.