CVE-2026-105141
topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
| CWE | CWE-798 CWE-259 |
| Vendor | topoteretes |
| Product | cognee |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for topoteretes cognee
Be the first to know when new medium vulnerabilities affecting topoteretes cognee are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
topoteretes / cognee
1.5.0 1.5.1 1.5.2 1.5.3 1.5.4
References
vuldb.com: https://vuldb.com/vuln/413365 vuldb.com: https://vuldb.com/vuln/413365/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105141 vuldb.com: https://vuldb.com/submit/944531 github.com: https://github.com/topoteretes/cognee/pull/5062 linear.app: https://linear.app/cognee/issue/SDK-720/replace-the-super-secret-fallback-for-token-signing-secrets-with-a-per github.com: https://github.com/topoteretes/cognee/commit/fa65fc0cd86cdba48d19aa76e36be862be982f5d github.com: https://github.com/topoteretes/cognee/releases/tag/v1.6.0 github.com: https://github.com/topoteretes/cognee/
Credits
๐ zhuke (VulDB User)