CVE-2026-105392: Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRETKEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of Lybbn Django-Vue-Lyadmin up to version 3.2.12 are affected if they use the hard-coded SECRET_KEY in backend/application/settings.py rather than replacing it before deployment.
What does an attacker need to exploit it?
The issue can be exploited remotely and requires no privileges or user interaction. Public exploit information is available, increasing the likelihood of attempted exploitation.
What should teams do if they have deployed the default key?
Replace the JWT signing SECRET_KEY with a unique, securely generated secret before deployment. The maintainer states that developers must manually change the key.