. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." | |
| Title | Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key | |
| First Time appeared |
Lybbn
Lybbn django-vue-lyadmin |
|
| Weaknesses | CWE-320 CWE-321 |
|
| CPEs | cpe:2.3:a:lybbn:django-vue-lyadmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lybbn
Lybbn django-vue-lyadmin |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T19:45:12.468Z
Reserved: 2026-10-05T10:38:25.971Z
Link: CVE-2026-105392
No data.
Status : Received
Published: 2026-10-05T20:17:10.827
Modified: 2026-10-05T20:17:10.827
Link: CVE-2026-105392
No data.
OpenCVE Enrichment
No data.