The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
The production build
Vulnerability
CVE-2026-49191
NVD
Refer to CVE-2026-49191 NVD advisory