Information Exposure in Flame through 2.4.0 by Pawel Malak
CVE-2026-100418
6.9MEDIUM
What is CVE-2026-100418?
An information exposure vulnerability exists in Flame version 2.4.0 due to the unauthenticated GET /api/config endpoint. This flaw allows attackers to access the full configuration object, including sensitive components such as the weather API key and internal operational settings, without authentication. By sending a single unauthorized request, malicious actors can exploit this vulnerability to consume service quotas or disclose critical configuration details. Proper authentication measures are essential to secure sensitive information.
Affected Version(s)
flame 0 <= 2.4.0
