VYPR

Llamafarm

by Llama Farm

CVEs (1)

  • CVE-2026-108760HigOct 11, 2026
    risk 0.49cvss 7.6epss —

    LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read…