Loading market data...
← Back to CVE feed

CVE-2026-100418

MEDIUM CVSS 5.3 View on NVD ↗

Description

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 25, 2026 22:17 UTC Modified: Sep 25, 2026 22:17 UTC