CVE-2026-108760

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,2
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,6
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: high

Description

AI Translation Available

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.

1327

Binding to an Unrestricted IP Address

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Applicable Platforms
Languages: Other
Technologies: Web Server, Client Server, Cloud Computing
View CWE Details
https://github.com/llama-farm/llamafarm
https://github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa3964529…
https://github.com/llama-farm/llamafarm/blob/853e7eabdf70dd78054d93fabfa3964529…
https://hackmd.io/@haind03/llamafarm-default-all-interface-bind-unauthenticated…
https://www.vulncheck.com/advisories/llamafarm-through-0.0.34-unauthenticated-a…