Sceawere

Vulnerability Detail

CVE-2026-108760UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LlamaFarm Unauthenticated Remote Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
4h ago
Vendor
llama-farm
Product
llamafarm
Attack Type
Binding to an Unrestricted IP Address
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-10-11T13:17:21.310Z",
  "pubdate": "2026-10-11T13:17:21.310Z",
  "executiveSummary": "LlamaFarm versions through 0.0.34 are susceptible to an insecure default configuration vulnerability that exposes the FastAPI management interface to all network interfaces.\nThe application binds the service to 0.0.0.0 on port 14345 by default, combined with a failure in the CLI to honor host configuration overrides, effectively preventing administrators from restricting access to localhost.\nThis vulnerability grants network-adjacent attackers the ability to interact with the project and dataset management API without any form of authentication.\nThe potential impact includes unauthorized extraction of sensitive information, such as provider API keys, as well as destructive actions including the unauthorized modification of project configurations and the irreversible deletion of datasets.\nBecause the service lacks mandatory authentication mechanisms, the exploitation requirements are minimal, necessitating only network visibility to the targeted host and port.\nThis poses a critical risk to data confidentiality, integrity, and availability for deployments where the service is reachable via an untrusted network.",
  "technicalDetails": "The vulnerability resides in the application's network binding implementation within the FastAPI service stack. By default, the service is configured to listen on all available network interfaces (0.0.0.0) at port 14345. This configuration decision effectively bypasses intended access control patterns that would otherwise restrict the API service to the loopback interface (127.0.0.1) for local-only interaction.\nA secondary failure exists within the 'lf' CLI utility, which contains logic to accept host overrides but silently discards them during the server startup process. Consequently, even when an operator attempts to enforce a stricter binding configuration, the application remains exposed to the wider network.\nThe exploitation flow begins with a network-adjacent attacker identifying the service listening on port 14345 via standard reconnaissance techniques. Since the API does not require authentication for any endpoint, the attacker can interact with the system management API directly using common HTTP clients or command-line tools.\nUpon successful connectivity, the attacker can leverage the following attack surface: 1) Information Disclosure: The attacker can query the project and dataset management API to retrieve sensitive stored credentials, specifically provider API keys used for downstream services. 2) Data Manipulation: The attacker can modify existing project configurations, potentially redirecting ingestion pipelines or altering processing parameters. 3) Denial of Service / Destructive Action: The attacker can trigger ingestion processes or issue commands to irreversibly delete projects and associated datasets, leading to permanent data loss.\nThe root cause is a combination of insecure default network binding policies and a broken configuration parsing mechanism in the CLI wrapper. Because the FastAPI server is initialized without middleware or security decorators to enforce authentication, all registered routes are publicly accessible. The vulnerability affects all versions up to and including 0.0.34 and persists as long as the application is hosted in environments where the 14345/tcp port is not blocked by external perimeter firewalls or host-based access control lists (ACLs)."
}
CVE-2026-108760: LlamaFarm Unauthenticated Remote Access Vulnerability (HIGH Severity, CVSS: 7.6) | Sceawere