Search

Find a vulnerability

Search criteria

    6 vulnerabilities by pawelmalak

    CVE-2026-100502 (GCVE-0-2026-100502)

    Vulnerability from nvd – Published: 2026-09-25 22:04 – Updated: 2026-09-30 00:13
    VLAI
    Title
    Flame through 2.4.0 Admin Token Insufficient Session Expiration
    Summary
    Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 00:12 UTC
    CWE
    • CWE-613 - Insufficient Session Expiration
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100502",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T00:12:58.424687Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T00:13:26.591Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/pawelmalak/flame/issues/494"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Whispergate Security Research"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "Insufficient Session Expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:02.084Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 5)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "login passes client-supplied duration to signToken",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L9-L17"
            },
            {
              "name": "JWT signed with caller-chosen expiresIn",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/utils/signToken.js#L4"
            },
            {
              "name": "JWT secret persisted once in data/.secret, never rotated",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/utils/init/initSecret.js#L8-L25"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Admin Token Insufficient Session Expiration",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-admin-token-insufficient-session-expiration"
            }
          ],
          "title": "Flame through 2.4.0 Admin Token Insufficient Session Expiration",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100502",
        "datePublished": "2026-09-25T22:04:02.084Z",
        "dateReserved": "2026-09-25T21:55:56.367Z",
        "dateUpdated": "2026-09-30T00:13:26.591Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100501 (GCVE-0-2026-100501)

    Vulnerability from nvd – Published: 2026-09-25 22:04 – Updated: 2026-09-25 22:04
    VLAI
    Title
    Flame through 2.4.0 Brute-Force Attack via Login Endpoint
    Summary
    Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration.
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Whispergate Security Research"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:01.425Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 1)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "POST /api/auth registered with no rate limiting",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/routes/auth.js#L7"
            },
            {
              "name": "login compares the single admin password and issues a JWT",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L11-L22"
            },
            {
              "name": "Docker image default PASSWORD",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/.docker/Dockerfile#L28"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-brute-force-attack-via-login-endpoint"
            }
          ],
          "title": "Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100501",
        "datePublished": "2026-09-25T22:04:01.425Z",
        "dateReserved": "2026-09-25T21:39:02.327Z",
        "dateUpdated": "2026-09-25T22:04:01.425Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100418 (GCVE-0-2026-100418)

    Vulnerability from nvd – Published: 2026-09-25 22:04 – Updated: 2026-09-29 17:39
    VLAI
    Title
    Flame through 2.4.0 Information Exposure via GET /api/config
    Summary
    Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:37 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100418",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:37:12.610139Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:39:22.712Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/pawelmalak/flame/issues/494"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:00.085Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 4)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "getConfig.js returns full config without redaction",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/controllers/config/getConfig.js#L7-L13"
            },
            {
              "name": "GET /api/config registered without auth middleware",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/routes/config.js#L14"
            },
            {
              "name": "WEATHER_API_KEY is part of the config object",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/utils/init/initialConfig.json#L2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Information Exposure via GET /api/config",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-information-exposure-via-get-api-config"
            }
          ],
          "title": "Flame through 2.4.0 Information Exposure via GET /api/config",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100418",
        "datePublished": "2026-09-25T22:04:00.085Z",
        "dateReserved": "2026-09-25T20:30:44.073Z",
        "dateUpdated": "2026-09-29T17:39:22.712Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100502 (GCVE-0-2026-100502)

    Vulnerability from cvelistv5 – Published: 2026-09-25 22:04 – Updated: 2026-09-30 00:13
    VLAI
    Title
    Flame through 2.4.0 Admin Token Insufficient Session Expiration
    Summary
    Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 00:12 UTC
    CWE
    • CWE-613 - Insufficient Session Expiration
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100502",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T00:12:58.424687Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T00:13:26.591Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/pawelmalak/flame/issues/494"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Whispergate Security Research"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "Insufficient Session Expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:02.084Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 5)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "login passes client-supplied duration to signToken",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L9-L17"
            },
            {
              "name": "JWT signed with caller-chosen expiresIn",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/utils/signToken.js#L4"
            },
            {
              "name": "JWT secret persisted once in data/.secret, never rotated",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/utils/init/initSecret.js#L8-L25"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Admin Token Insufficient Session Expiration",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-admin-token-insufficient-session-expiration"
            }
          ],
          "title": "Flame through 2.4.0 Admin Token Insufficient Session Expiration",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100502",
        "datePublished": "2026-09-25T22:04:02.084Z",
        "dateReserved": "2026-09-25T21:55:56.367Z",
        "dateUpdated": "2026-09-30T00:13:26.591Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100501 (GCVE-0-2026-100501)

    Vulnerability from cvelistv5 – Published: 2026-09-25 22:04 – Updated: 2026-09-25 22:04
    VLAI
    Title
    Flame through 2.4.0 Brute-Force Attack via Login Endpoint
    Summary
    Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration.
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Whispergate Security Research"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:01.425Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 1)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "POST /api/auth registered with no rate limiting",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/routes/auth.js#L7"
            },
            {
              "name": "login compares the single admin password and issues a JWT",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/controllers/auth/login.js#L11-L22"
            },
            {
              "name": "Docker image default PASSWORD",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/v2.4.0/.docker/Dockerfile#L28"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-brute-force-attack-via-login-endpoint"
            }
          ],
          "title": "Flame through 2.4.0 Brute-Force Attack via Login Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100501",
        "datePublished": "2026-09-25T22:04:01.425Z",
        "dateReserved": "2026-09-25T21:39:02.327Z",
        "dateUpdated": "2026-09-25T22:04:01.425Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100418 (GCVE-0-2026-100418)

    Vulnerability from cvelistv5 – Published: 2026-09-25 22:04 – Updated: 2026-09-29 17:39
    VLAI
    Title
    Flame through 2.4.0 Information Exposure via GET /api/config
    Summary
    Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:37 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    pawelmalak flame Affected: 0 , ≤ 2.4.0 (custom)
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100418",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:37:12.610139Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:39:22.712Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/pawelmalak/flame/issues/494"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "flame",
              "vendor": "pawelmalak",
              "versions": [
                {
                  "lessThanOrEqual": "2.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lazizbek Djurayev (Haad TC)"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-25T22:04:00.085Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #494 (finding 4)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pawelmalak/flame/issues/494"
            },
            {
              "name": "getConfig.js returns full config without redaction",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/controllers/config/getConfig.js#L7-L13"
            },
            {
              "name": "GET /api/config registered without auth middleware",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/routes/config.js#L14"
            },
            {
              "name": "WEATHER_API_KEY is part of the config object",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/pawelmalak/flame/blob/3e03c25138df4321143c4fbd1a99468ff375ebb2/utils/init/initialConfig.json#L2"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/pawelmalak/flame"
            },
            {
              "name": "VulnCheck Advisory: Flame through 2.4.0 Information Exposure via GET /api/config",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/flame-through-2.4.0-information-exposure-via-get-api-config"
            }
          ],
          "title": "Flame through 2.4.0 Information Exposure via GET /api/config",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100418",
        "datePublished": "2026-09-25T22:04:00.085Z",
        "dateReserved": "2026-09-25T20:30:44.073Z",
        "dateUpdated": "2026-09-29T17:39:22.712Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }