Product
LlamaFarm versions 0.0.34 and earlier contain an insecure default configuration that binds an unauthenticated FastAPI service to all network interfaces, allowing remote attackers to exfiltrate API keys and manipulate project data.