Medium severity5.3NVD Advisory· Published Sep 25, 2026
CVE-2026-100418
CVE-2026-100418
Description
Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data.
Affected products
1- Range: <=2.4.0
Patches
Vulnerability mechanics
References
5- github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/controllers/config/getConfig.jsnvd
- github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/routes/config.jsnvd
- github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/utils/init/initialConfig.jsonnvd
- github.com/pawelmalak/flame/issues/494nvd
- www.vulncheck.com/advisories/flame-through-2.4.0-information-exposure-via-get-api-confignvd
News mentions
0No linked articles in our index yet.