Unauthenticated FastAPI Server Vulnerability in LlamaFarm by LlamaFarm
CVE-2026-108760

7.2HIGH

Key Information:

Vendor

Llama-farm

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108760?

LlamaFarm versions up to 0.0.34 contain an insecure default configuration that exposes an unauthenticated FastAPI server. This server binds to all interfaces, enabling network-adjacent attackers to access various APIs without proper authentication. They can exploit this vulnerability to read sensitive provider API keys, modify existing projects, initiate data ingestion processes, and even delete projects irreversibly. The lf CLI tool does not honor HOST overrides, compounding the risk by allowing unrestricted access to critical functionality.

Affected Version(s)

llamafarm 0 <= 0.0.34

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.