Description
LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.
Published: 2026-10-11
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Remote API Access
Action: Patch Immediately
AI Analysis

Impact

The vulnerability stems from an insecure default configuration in LlamaFarm versions up to 0.0.34. Its FastAPI server is bound to 0.0.0.0 on port 14345, and the command‑line interface ignores host overrides, exposing the management API without authentication. An attacker with network access can read stored provider API keys, modify projects, trigger data ingestion, and irreversibly delete projects, compromising both confidentiality and integrity. The weakness is classified as CWE‑1327, an unauthorized parameter binding issue.

Affected Systems

The affected product is LlamaFarm, version 0.0.34 or earlier. Adopters who have not upgraded beyond this release are vulnerable. No other vendor or product versions are indicated as impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate‑to‑high severity vulnerability. EPSS information is not provided, and the vulnerability is not listed in the CISA KEV catalog. A network‑adjacent attacker can exploit the flaw by sending HTTP requests to port 14345 on any interface that the service listens on. Because no authentication is required, the attacker can perform read and write operations on projects and secrets with no further configuration.

Generated by OpenCVE AI on October 11, 2026 at 13:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LlamaFarm to the latest release where the unauthenticated binding has been removed.
  • Reconfigure the application to bind the FastAPI server to a local IP address such as 127.0.0.1 or to a restricted interface, ensuring that host overrides are respected.
  • Block external access to port 14345 using a firewall or network ACL so that only trusted hosts can reach the management API.

Generated by OpenCVE AI on October 11, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.
Title LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces
Weaknesses CWE-1327
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:57.155Z

Reserved: 2026-10-11T01:57:28.678Z

Link: CVE-2026-108760

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:21.310

Modified: 2026-10-11T13:17:21.310

Link: CVE-2026-108760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-1327

    Binding to an Unrestricted IP Address