CVE-2026-105392 | Lybbn Django-Vue-Lyadmin up to 3.2.12 JWT Signing settings.py SECRET_KEY hard-coded key
A vulnerability marked as critical has been reported in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
.
This vulnerability is referenced as CVE-2026-105392. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project maintainer explains: “The issue with this key is described in the documentation. Developers need to manually change their keys before deployment.”VulDB Recent EntriesRead More