HIGH
llama-farm
CVE published 2026-10-11
CVE-2026-108760
CVE-2026-108760 debrief: LlamaFarm unauthenticated API exposed on all interfaces due to insecure default configuration. Network-adjacent attackers can access project and dataset management API, potentially leading to unauthorized reading of stored provider API keys, modification of projects, triggering ingestion, and irreversible deletion of projects. Defenders should verify exposure, prioritize remediati [truncated]