PatchSiren

topoteretes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM topoteretes CVE published 2026-10-04

CVE-2026-105141

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is suffi [truncated]

CRITICAL topoteretes CVE published 2026-07-07

CVE-2026-58473

CVE-2026-58473 is an improper access control vulnerability in Cognee before 1.2.0. This vulnerability allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Consequently, attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint, enabli [truncated]