CVE-2026-105141
Received Received - Intake

Hard-Coded JWT Secret in Cognee

Vulnerability report for CVE-2026-105141, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
topoteretes cognee to 1.5.4 (inc)
topoteretes cognee 1.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a security flaw in the Cognee SDK up to version 1.5.4 where authentication token secrets defaulted to a hardcoded value ('super_secret') if environment variables were not set. This allowed attackers to forge tokens using a known key, compromising authentication security in deployments where secrets were not explicitly configured.

Detection Guidance

Check if the environment variable FASTAPI_USERS_JWT_SECRET is set to a default or hardcoded value like 'super_secret' in your Cognee configuration. Inspect the JWT signing key handler in cognee/modules/users/authentication/get_api_auth_backend.py for hardcoded secrets. Verify if tokens can be forged using a known key by testing authentication flows.

Impact Analysis

An attacker could forge authentication tokens to gain unauthorized access to the system, potentially leading to data breaches, privilege escalation, or impersonation of legitimate users. Tokens signed with the hardcoded secret are vulnerable to forgery, allowing attackers to bypass authentication mechanisms.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Compliance may be compromised if authentication mechanisms are bypassed, potentially resulting in data breaches and regulatory penalties.

Mitigation Strategies

Upgrade to Cognee version 1.6.0 or later to apply the patch. Explicitly set strong, unique JWT secrets in environment variables for all replicas to ensure token persistence and cross-replica compatibility. Review and update your .env files and deployment documentation to reflect the new secret handling behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105141. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart