CVE-2026-108760
Received Received - Intake

Insecure Default Binding in LlamaFarm FastAPI Server

Vulnerability report for CVE-2026-108760, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
llama-farm llamafarm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1327 The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

LlamaFarm through version 0.0.34 has an insecure default setup where its FastAPI server is exposed on all network interfaces (0.0.0.0) on port 14345 without authentication. Attackers on the same network can exploit this to access sensitive data like API keys, modify projects, trigger data ingestion, or permanently delete projects.

Detection Guidance

Check if the LlamaFarm server is running on port 14345 by using commands like 'netstat -tulnp | grep 14345' or 'ss -tulnp | grep 14345'. If the server is bound to 0.0.0.0, it is exposed to network attacks.

Impact Analysis

If you use LlamaFarm, attackers could steal your API keys, alter your projects, force unwanted data processing, or delete your work. This could lead to data breaches, service disruption, or unauthorized access to connected systems.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data or HIPAA by leaking protected health information. Unauthorized access to API keys may also breach compliance requirements for data protection and access controls.

Mitigation Strategies

Update LlamaFarm to the latest version where this issue is fixed. If an update is not available, restrict access to port 14345 using firewall rules or bind the server to 127.0.0.1 instead of 0.0.0.0.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108760. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart