Impact
The vulnerability stems from an insecure default configuration in LlamaFarm versions up to 0.0.34. Its FastAPI server is bound to 0.0.0.0 on port 14345, and the command‑line interface ignores host overrides, exposing the management API without authentication. An attacker with network access can read stored provider API keys, modify projects, trigger data ingestion, and irreversibly delete projects, compromising both confidentiality and integrity. The weakness is classified as CWE‑1327, an unauthorized parameter binding issue.
Affected Systems
The affected product is LlamaFarm, version 0.0.34 or earlier. Adopters who have not upgraded beyond this release are vulnerable. No other vendor or product versions are indicated as impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity vulnerability. EPSS information is not provided, and the vulnerability is not listed in the CISA KEV catalog. A network‑adjacent attacker can exploit the flaw by sending HTTP requests to port 14345 on any interface that the service listens on. Because no authentication is required, the attacker can perform read and write operations on projects and secrets with no further configuration.
OpenCVE Enrichment