<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LlamaFarm - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/llamafarm/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/llamafarm/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>LlamaFarm Insecure Default Configuration and Unauthenticated API Access</title><link>https://feed.craftedsignal.io/briefs/2026-10-llamafarm-insecure-config/</link><pubDate>Sun, 11 Oct 2026 14:01:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-llamafarm-insecure-config/</guid><description>LlamaFarm versions 0.0.34 and earlier contain an insecure default configuration that binds an unauthenticated FastAPI service to all network interfaces, allowing remote attackers to exfiltrate API keys and manipulate project data.</description><content:encoded><![CDATA[<p>LlamaFarm versions through 0.0.34 suffer from an insecure default configuration that exposes the internal FastAPI management server to all network interfaces by binding it to 0.0.0.0 on port 14345. Additionally, the lf command-line interface fails to honor host overrides, preventing administrators from restricting access to the local loopback interface. This vulnerability allows network-adjacent attackers to interact directly with the project and dataset management API without any form of authentication. By sending crafted HTTP requests, an attacker can exfiltrate sensitive provider API keys stored within the application, modify existing projects, trigger unauthorized data ingestion processes, or perform destructive actions such as the irreversible deletion of projects. This exposure creates significant risk for organizations using LlamaFarm in environments accessible from broader network segments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized third parties to gain full control over the LlamaFarm application. The impact includes the exfiltration of sensitive third-party API credentials, the potential poisoning or unauthorized modification of datasets, and data loss due to the ability to delete projects. Given the nature of project management APIs, this could result in significant operational disruption and compromise of upstream services authenticated by the exfiltrated keys.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade LlamaFarm to the latest version immediately to remediate the default binding configuration.</li>
<li>Implement network segmentation to ensure port 14345 is not reachable from untrusted network segments.</li>
<li>Apply host-based firewall rules to explicitly restrict access to port 14345 to known authorized management IP addresses.</li>
<li>Audit logs for the LlamaFarm API endpoint for any unauthorized POST, PUT, or DELETE requests from unexpected source IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>