GHSA-5gfh-7q6r-6q5pMediumCVSS 7.3
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-105392
- https://github.com/lybbn/django-vue-lyadmin/issues/3
- https://github.com/lybbn/django-vue-lyadmin
- https://vuldb.com/cve/CVE-2026-105392
- https://vuldb.com/submit/982747
- https://vuldb.com/vuln/413586
- https://vuldb.com/vuln/413586/cti
- https://github.com/advisories/GHSA-5gfh-7q6r-6q5p