GHSA-xrgh-2vxr-rhm4MediumCVSS 6.3

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is...

Published
October 4, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (1)

📋 Description

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.

🔗 References (11)