CVE-2026-105392
Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
| CWE | CWE-321 CWE-320 |
| Vendor | lybbn |
| Product | django-vue-lyadmin |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for lybbn django-vue-lyadmin
Be the first to know when new high vulnerabilities affecting lybbn django-vue-lyadmin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Lybbn / Django-Vue-Lyadmin
3.2.0 3.2.1 3.2.2 3.2.3 3.2.4 3.2.5 3.2.6 3.2.7 3.2.8 3.2.9 3.2.10 3.2.11 3.2.12
References
Credits
๐ HiiragiHaru (VulDB User) VulDB CNA Team