Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 04 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised. | |
| Title | topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials | |
| First Time appeared |
Topoteretes
Topoteretes cognee |
|
| Weaknesses | CWE-259 CWE-798 |
|
| CPEs | cpe:2.3:a:topoteretes:cognee:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Topoteretes
Topoteretes cognee |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-04T07:45:15.985Z
Reserved: 2026-10-03T14:26:06.555Z
Link: CVE-2026-105141
No data.
Status : Received
Published: 2026-10-04T09:16:39.203
Modified: 2026-10-04T09:16:39.203
Link: CVE-2026-105141
No data.
OpenCVE Enrichment
Updated: 2026-10-04T11:30:12Z