CVE-2026-108760
HIGH
7,2
Source: [email protected]
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
7,6
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: high
Description
AI Translation Available
LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.
1327
Binding to an Unrestricted IP Address
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Applicable Platforms
Languages:
Other
Technologies:
Web Server, Client Server, Cloud Computing
https://github.com/llama-farm/llamafarm
https://github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa3964529…
https://github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa3964529…
https://hackmd.io/@haind03/llamafarm-default-all-interface-bind-unauthenticated…
https://www.vulncheck.com/advisories/llamafarm-through-0.0.34-unauthenticated-a…