PatchSiren

llama-farm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH llama-farm CVE published 2026-10-11

CVE-2026-108760

CVE-2026-108760 debrief: LlamaFarm unauthenticated API exposed on all interfaces due to insecure default configuration. Network-adjacent attackers can access project and dataset management API, potentially leading to unauthorized reading of stored provider API keys, modification of projects, triggering ingestion, and irreversible deletion of projects. Defenders should verify exposure, prioritize remediati [truncated]