Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105141— topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials

Quick assessment

Affected
topoteretes cognee
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 topoteretes cognee 1.5.4 及之前版本中发现了一个安全漏洞。受影响的组件是 JWT 签名密钥处理器(JWT Signing Key Handler)中的函数 ,该函数位于文件 中。对参数 的操作会导致出现硬编码凭据的问题。此漏洞可被远程利用。升级至 1.6.0 版本即可修复该问题。该补丁的提交标识为 fa65fc0cd86cdba48d19aa76e36be862be982f5d。建议尽快升级受影响的组件。

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1552 · Unsecured Credentials
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105141

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials
Source: CVE Program / CVE List V5
Vulnerability Description
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
topoteretes cognee 1.5.0 cpe:2.3:a:topoteretes:cognee:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105141

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105141

请登录查看更多情报信息。

Other References for CVE-2026-105141 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105141

No comments yet


Leave a comment