Description
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
Published: 2026-10-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote exploitation via hard‑coded JWT signing secret
Action: Upgrade Now
AI Analysis

Impact

The flaw resides in the get_user_id_by_email function within Cognee’s authentication module, where a hard‑coded JWT signing key is used when manipulating the FASTAPI_USERS_JWT_SECRET argument. This weakness enables an attacker to generate valid JWT tokens without knowing the legitimate secret, potentially allowing unauthorized access to protected endpoints. The vulnerability is rated with a CVSS score of 5.3, indicating a medium severity that can be exploited remotely, though no exploitation probability data (EPSS) is available and the issue is not listed in the CISA KEV catalog.

Affected Systems

The affected product is topoteretes Cognee, versions up to 1.5.4. The product is available from the official GitHub repository and newer releases contain the fix. Upgrading to version 1.6.0 removes the hard‑coded key and replaces it with a proper secret handling mechanism.

Risk and Exploitability

The risk remains moderate due to the medium CVSS score; based on the description, it is inferred that exploitation would require only knowledge of the application’s code or configuration to identify the hard‑coded value. Without a listed EPSS score, precise likelihood cannot be quantified, but the absence of a KEV entry suggests current exploitation activity is not widespread. Attackers could remotely construct JWTs to gain unauthorized access, which could compromise confidentiality and integrity of user data. No additional prerequisites are identified beyond the capability to read the token secret.

Generated by OpenCVE AI on October 4, 2026 at 11:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cognee to version 1.6.0 or later, which removes the hard‑coded JWT signing key.
  • Configure an environment variable or secure secret store for FASTAPI_USERS_JWT_SECRET to prevent hard‑coded credentials.
  • Ensure the authentication module no longer references a default secret and verifies that all JWTs are signed with the configured secret.
  • Monitor authentication logs for unexpected token validation successes that may indicate misuse of a hard‑coded secret.

Generated by OpenCVE AI on October 4, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
Title topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-coded credentials
First Time appeared Topoteretes
Topoteretes cognee
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:topoteretes:cognee:*:*:*:*:*:*:*:*
Vendors & Products Topoteretes
Topoteretes cognee
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Topoteretes Cognee
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T07:45:15.985Z

Reserved: 2026-10-03T14:26:06.555Z

Link: CVE-2026-105141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T09:16:39.203

Modified: 2026-10-04T09:16:39.203

Link: CVE-2026-105141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T11:30:12Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials