Flame · Flame · CVE-2026-100418
**Name of the Vulnerable Software and Affected Versions**
Flame versions prior to 2.4.1
**Description**
An information exposure issue exists in the unauthenticated 'GET /api/config' endpoint, which returns the complete configuration object without redacting sensitive fields. This allows an attacker to retrieve internal operational settings and the stored weather API key by sending a single unauthenticated request, potentially leading to the consumption of provider quotas or unauthorized access to sensitive data.
**Recommendations**
Update Flame to version 2.4.1 or later.
As a temporary mitigation, restrict access to the 'GET /api/config' endpoint.