. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." | |
| Title | Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key | |
| First Time appeared |
Lybbn
Lybbn django-vue-lyadmin |
|
| Weaknesses | CWE-320 CWE-321 |
|
| CPEs | cpe:2.3:a:lybbn:django-vue-lyadmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lybbn
Lybbn django-vue-lyadmin |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T19:45:12.468Z
Reserved: 2026-10-05T10:38:25.971Z
Link: CVE-2026-105392
No data.
Status : Received
Published: 2026-10-05T20:17:10.827
Modified: 2026-10-05T20:17:10.827
Link: CVE-2026-105392
No data.
OpenCVE Enrichment
No data.