CVE-2026-105141 | topoteretes cognee up to 1.5.4 JWT Signing Key get_api_auth_backend.py get_user_id_by_email FASTAPI_USERS_JWT_SECRET hard-coded credentials (ID 5062)
A vulnerability classified as critical was found in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials.
This vulnerability is cataloged as CVE-2026-105141. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More