Unauthenticated FastAPI Server Vulnerability in LlamaFarm by LlamaFarm
CVE-2026-108760
7.2HIGH
What is CVE-2026-108760?
LlamaFarm versions up to 0.0.34 contain an insecure default configuration that exposes an unauthenticated FastAPI server. This server binds to all interfaces, enabling network-adjacent attackers to access various APIs without proper authentication. They can exploit this vulnerability to read sensitive provider API keys, modify existing projects, initiate data ingestion processes, and even delete projects irreversibly. The lf CLI tool does not honor HOST overrides, compounding the risk by allowing unrestricted access to critical functionality.
Affected Version(s)
llamafarm 0 <= 0.0.34
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
