{"id":"CVE-2026-105141","title":"A security flaw has been discovered in topoteretes cognee up to 1.5.4","summary":"A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Han…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-259","CWE-798"],"vendor":"topoteretes","product":"cognee","affected":["cognee 1.5.0","cognee 1.5.1","cognee 1.5.2","cognee 1.5.3","cognee 1.5.4"],"published":"2026-10-04","updated":"2026-10-04","sourceUpdated":"2026-10-04T09:16:39.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105141","references":[{"url":"https://github.com/topoteretes/cognee/","label":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/commit/fa65fc0cd86cdba48d19aa76e36be862be982f5d","label":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/pull/5062","label":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/releases/tag/v1.6.0","label":"cna@vuldb.com"},{"url":"https://linear.app/cognee/issue/SDK-720/replace-the-super-secret-fallback-for-token-signing-secrets-with-a-per","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105141","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/944531","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413365","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413365/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-04T08:56:28.291Z","slug":"CVE-2026-105141","body":"## Overview\n\nA security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}