Sceawere
Vulnerability Detail
CVE-2026-101052UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Refly Hard-Coded JWT Credentials
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 4h ago
- Vendor
- refly-ai
- Product
- refly
- Attack Type
- Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T12:17:35.977Z",
"pubdate": "2026-09-28T12:17:35.977Z",
"executiveSummary": "A critical security vulnerability identified as hard-coded credentials has been discovered in refly-ai refly versions up to 1.1.0.\nThe vulnerability resides within the JWT Token Handler, specifically affecting the configuration logic located in apps/api/src/modules/config/app.config.ts.\nThis flaw allows remote attackers to potentially bypass authentication mechanisms by leveraging the static, hard-coded sensitive information embedded within the source code.\nThe presence of hard-coded credentials represents a severe security risk, as it circumvents standard access control measures and facilitates unauthorized access to the application.\nGiven that the exploit has been disclosed publicly and the vendor has not responded to vulnerability disclosures, the risk of active exploitation is significant.\nSuccessful exploitation requires no prior authentication, as the credentials can be identified by inspecting the application configuration logic, granting the attacker the ability to forge or manipulate JWT tokens remotely.",
"technicalDetails": "The vulnerability is classified as an improper storage of sensitive information, specifically hard-coded credentials within the application's configuration module. The affected file, apps/api/src/modules/config/app.config.ts, contains static secrets used by the JWT Token Handler to sign or verify JSON Web Tokens.\nIn a secure implementation, JWT secrets should be managed through secure environment variables or a dedicated secrets management service. However, in refly-ai refly version 1.1.0 and earlier, the secret key is hard-coded directly into the source code, making it visible to anyone with access to the codebase or the deployed application package.\nThe attack flow initiates when an adversary gains access to the application's source code or the deployed configuration file. By inspecting apps/api/src/modules/config/app.config.ts, the attacker extracts the hard-coded JWT secret.\nOnce the secret is obtained, the attacker can move to the exploitation phase. Because the JWT Token Handler relies on this static, known secret, the attacker can craft malicious JWTs. By manually signing a token with the compromised secret and setting arbitrary claims—such as administrative user IDs—the attacker can bypass the application's authentication layer.\nThe impact of this vulnerability is total authentication bypass. An attacker can impersonate any user, including administrative accounts, to gain unauthorized access to protected API endpoints and sensitive data processed by the refly application. The attack is remotely executable, as the attacker only needs to send a request containing the forged, validly-signed JWT to the target API.\nThe vulnerability is persistent across all deployments of refly-ai refly up to version 1.1.0 that utilize the default hard-coded configuration. There is no complex exploitation chain required, as the credential exposure provides the necessary prerequisites for immediate unauthorized session manipulation. The post-exploitation impact includes full system compromise, unauthorized data access, and potential manipulation of application logic through elevated privileges."
}