CVE-2026-105141
Last modified
CVE-2026-105141 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler.
Description
A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| topoteretes | cognee | 1.5.0; 1.5.1; 1.5.2; 1.5.3; 1.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-105141?
How severe is CVE-2026-105141?
How do I fix CVE-2026-105141?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105131ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escala…5.4
- CVE-2026-105133A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2.…7.3
- CVE-2026-105134A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This v…10
- CVE-2026-105135A vulnerability has been found in InternLM MindSearch 0.1.0.…10
- CVE-2026-105137A vulnerability was found in Laradock up to 20.4. Impacted i…5
- CVE-2026-10514A vulnerability has been found in 1Panel-dev CordysCRM up to…2.4
- CVE-2026-105144A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 o…5.3
- CVE-2026-105145A vulnerability has been found in Weaviate Verba up to 2.1.3…5.3
- CVE-2026-105146A vulnerability was found in Comsenz Discuz! X5.0-20260801/X…4.7
- CVE-2026-105147A vulnerability was determined in SciPhi-AI R2R up to 3.6.6.…7.3
- CVE-2026-105148A vulnerability was identified in SciPhi-AI R2R up to 3.6.6.…7.3
- CVE-2026-105149A security flaw has been discovered in mooSocial up to 3.2.4…7.3
Are you affected by CVE-2026-105141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
