๐Ÿ” CVE Alert

CVE-2026-105141

MEDIUM 6.3

topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.

CWE CWE-798 CWE-259
Vendor topoteretes
Product cognee
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for topoteretes cognee

Be the first to know when new medium vulnerabilities affecting topoteretes cognee are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

topoteretes / cognee
1.5.0 1.5.1 1.5.2 1.5.3 1.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/413365 vuldb.com: https://vuldb.com/vuln/413365/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105141 vuldb.com: https://vuldb.com/submit/944531 github.com: https://github.com/topoteretes/cognee/pull/5062 linear.app: https://linear.app/cognee/issue/SDK-720/replace-the-super-secret-fallback-for-token-signing-secrets-with-a-per github.com: https://github.com/topoteretes/cognee/commit/fa65fc0cd86cdba48d19aa76e36be862be982f5d github.com: https://github.com/topoteretes/cognee/releases/tag/v1.6.0 github.com: https://github.com/topoteretes/cognee/

Credits

๐Ÿ” zhuke (VulDB User)