GHSA-xrgh-2vxr-rhm4MediumCVSS 6.3
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is...
🔗 CVE IDs covered (1)
📋 Description
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
🔗 References (11)
- https://nvd.nist.gov/vuln/detail/CVE-2026-105141
- https://github.com/topoteretes/cognee/pull/5062
- https://github.com/topoteretes/cognee/commit/fa65fc0cd86cdba48d19aa76e36be862be982f5d
- https://github.com/topoteretes/cognee
- https://github.com/topoteretes/cognee/releases/tag/v1.6.0
- https://linear.app/cognee/issue/SDK-720/replace-the-super-secret-fallback-for-token-signing-secrets-with-a-per
- https://vuldb.com/cve/CVE-2026-105141
- https://vuldb.com/submit/944531
- https://vuldb.com/vuln/413365
- https://vuldb.com/vuln/413365/cti
- https://github.com/advisories/GHSA-xrgh-2vxr-rhm4