Sceawere

Vulnerability Detail

CVE-2026-105141UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-coded JWT Secret Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
1d ago
Vendor
topoteretes
Product
cognee
Attack Type
Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-04T09:16:39.203Z",
  "pubdate": "2026-10-04T09:16:39.203Z",
  "executiveSummary": "A critical security vulnerability exists in topoteretes cognee up to version 1.5.4, involving the use of hard-coded credentials within the JWT signing mechanism.\nThe vulnerability is localized to the get_user_id_by_email function in cognee/modules/users/authentication/get_api_auth_backend.py, specifically concerning the handling of the FASTAPI_USERS_JWT_SECRET environment variable/configuration.\nThe flaw allows for unauthorized JWT token forgery, potentially enabling remote attackers to bypass authentication mechanisms and impersonate arbitrary users, including administrative accounts.\nThis represents a high-risk scenario as the secret key is embedded directly within the component, exposing the cryptographic material necessary to sign and validate session tokens.\nExploitation does not require prior authentication and can be performed remotely by any adversary capable of extracting the hard-coded secret from the application source code or distributed package.\nThe vulnerability is resolved by upgrading to version 1.6.0, which remediates the underlying credential management flaw.",
  "technicalDetails": "The vulnerability originates from the insecure implementation of the JWT signing key initialization within the JWT Signing Key Handler component. In affected versions of topoteretes cognee, the application retrieves the FASTAPI_USERS_JWT_SECRET through a mechanism that defaults to or utilizes hard-coded credentials rather than enforcing secure, dynamic environment-based injection.\nThe root cause is found within the get_user_id_by_email function, located in cognee/modules/users/authentication/get_api_auth_backend.py. During the authentication flow, the system references this static secret to validate incoming JSON Web Tokens. Because the secret is hard-coded into the application's logic, it is accessible to any entity with access to the source code or the deployed binary package.\nThe exploitation flow begins with the attacker obtaining the hard-coded FASTAPI_USERS_JWT_SECRET from the application's configuration or source files. Once the secret is retrieved, the attacker can leverage standard JWT libraries to forge arbitrary tokens. Specifically, the attacker can craft a payload containing user identity claims, such as 'user_id' or 'role', and sign these claims using the leaked secret key and the appropriate cryptographic algorithm (e.g., HS256).\nUpon presentation of a forged token to the affected endpoint, the application's authentication middleware—relying on the vulnerable get_api_auth_backend logic—will fail to detect the forgery because the signature matches the expected, albeit insecurely stored, static secret. Consequently, the application will treat the malicious token as a legitimate, authenticated session.\nThis vulnerability is classified as critical because it bypasses the primary security control (JWT authentication) entirely. An attacker does not require elevated privileges to initiate the attack; they merely require access to the secret key. The post-exploitation impact includes full unauthorized access to the affected instance, potential data exfiltration, and administrative control over the application's authenticated features. The vulnerability persists across all deployments of versions 1.5.4 and earlier, requiring an immediate transition to the secure handling model introduced in version 1.6.0 (patch identifier fa65fc0cd86cdba48d19aa76e36be862be982f5d)."
}
CVE-2026-105141: Hard-coded JWT Secret Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere