Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105392— Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key

Quick assessment

Affected
Lybbn Django-Vue-Lyadmin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Lybbn Django-Vue-Lyadmin 最高至 3.2.12 版本中发现了一个漏洞。受影响的元素是 JWT 签名组件中文件 的一个未知函数。对参数 的操作会导致使用硬编码的加密密钥。该漏洞可能被远程利用。此漏洞的利用方式已向公众披露,并可能被实际使用。项目维护者表示:“该密钥问题已在文档中说明。开发人员在部署前需要手动更改密钥。”

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1552.004 · Private Keys
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105392

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Lybbn Django-Vue-Lyadmin 3.2.0 cpe:2.3:a:lybbn:django-vue-lyadmin:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105392

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105392

请登录查看更多情报信息。

Proof of Concept for CVE-2026-105392 (1)

Other References for CVE-2026-105392 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105392

No comments yet


Leave a comment