MEDIUM 5.5 NVD
CVE-2026-105392
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
References
- https://github.com/lybbn/django-vue-lyadmin/
- https://github.com/lybbn/django-vue-lyadmin/issues/3
- https://vuldb.com/cve/CVE-2026-105392
- https://vuldb.com/submit/982747
- https://vuldb.com/vuln/413586
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.