Impact
The flaw resides in the get_user_id_by_email function within Cognee’s authentication module, where a hard‑coded JWT signing key is used when manipulating the FASTAPI_USERS_JWT_SECRET argument. This weakness enables an attacker to generate valid JWT tokens without knowing the legitimate secret, potentially allowing unauthorized access to protected endpoints. The vulnerability is rated with a CVSS score of 5.3, indicating a medium severity that can be exploited remotely, though no exploitation probability data (EPSS) is available and the issue is not listed in the CISA KEV catalog.
Affected Systems
The affected product is topoteretes Cognee, versions up to 1.5.4. The product is available from the official GitHub repository and newer releases contain the fix. Upgrading to version 1.6.0 removes the hard‑coded key and replaces it with a proper secret handling mechanism.
Risk and Exploitability
The risk remains moderate due to the medium CVSS score; based on the description, it is inferred that exploitation would require only knowledge of the application’s code or configuration to identify the hard‑coded value. Without a listed EPSS score, precise likelihood cannot be quantified, but the absence of a KEV entry suggests current exploitation activity is not widespread. Attackers could remotely construct JWTs to gain unauthorized access, which could compromise confidentiality and integrity of user data. No additional prerequisites are identified beyond the capability to read the token secret.
OpenCVE Enrichment