CVE-2026-101052
Deferred Deferred - Pending Action

Hard-Coded Credentials in Refly AI JWT Token Handler

Vulnerability report for CVE-2026-101052, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
refly-ai refly to 1.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a hard-coded default JWT secret ('test') in Refly AI versions up to 1.1.0. When the JWT_SECRET environment variable is not set, the system uses this weak secret, allowing attackers to forge HS256 access tokens if they know a victim's UID. This grants unauthorized access to sensitive data like user profiles and files.

Detection Guidance

Check Refly AI configuration files for hard-coded JWT secrets. Inspect apps/api/src/modules/config/app.config.ts for default values like 'test'. Verify environment variables to ensure JWT_SECRET is set and not using defaults.

Impact Analysis

Attackers can remotely forge valid JWT tokens to impersonate users, access sensitive endpoints, and steal or manipulate data such as user profiles, canvas data, and drive files. This requires knowing a victim's UID but enables full account takeover and unauthorized actions.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized data access and potential data breaches. It compromises confidentiality and integrity requirements, leading to non-compliance with security controls for protecting sensitive personal and health information.

Mitigation Strategies

Set a strong JWT_SECRET environment variable. Update Refly AI to the latest version. Rotate all existing JWT secrets. Review and enforce JWT configuration in documentation. Ensure auth guards verify user existence in the database.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101052. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart