Security Vulnerability in topoteretes cognee for JWT Signing Key Handling
CVE-2026-105141

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105141?

A security flaw has been identified in topoteretes cognee versions prior to 1.5.4, specifically within the get_user_id_by_email function located in the JWT Signing Key Handler component. Manipulation of the FASTAPI_USERS_JWT_SECRET argument can lead to the exposure of hard-coded credentials, potentially allowing remote attackers to exploit this vulnerability. To mitigate this risk, users are strongly advised to upgrade to version 1.6.0, which addresses this issue through a designated patch.

Affected Version(s)

cognee 1.5.0

cognee 1.5.1

cognee 1.5.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zhuke (VulDB User)
.