Skip to content
Threat Feed
high advisory

Hard-Coded Cryptographic Key in Django-Vue-Lyadmin JWT Signing

The Django-Vue-Lyadmin project up to version 3.2.12 contains a hard-coded SECRET_KEY in backend/application/settings.py, allowing remote attackers to forge JWT tokens and gain unauthorized access.

CVE search metadata

CVE search record: CVE-2026-105392. Severity: high. CVSS: 7.3. KEV: no. Product: Django-Vue-Lyadmin (<= 3.2.12). Brief: Hard-Coded Cryptographic Key in Django-Vue-Lyadmin JWT Signing. Brief link: https://feed.craftedsignal.io/briefs/2026-10-105392/

The Django-Vue-Lyadmin project (versions up to 3.2.12) contains a critical security vulnerability in its JWT Signing component. The file backend/application/settings.py includes a hard-coded SECRET_KEY, which is a common security flaw that allows attackers to predict or reconstruct cryptographic keys used for signing JSON Web Tokens (JWT). Because the key is publicly disclosed within the source code of the project, remote actors can manipulate the authentication process to sign their own tokens, effectively bypassing authentication mechanisms. This vulnerability has been publicly disclosed, and exploitation is possible. Maintainers indicate that developers must manually update this key before deployment, as the default state of the application is inherently insecure.

Impact

Successful exploitation of this vulnerability allows unauthorized actors to forge valid JWT tokens, leading to a complete compromise of the authentication system. Attackers can assume the identity of any user, including administrative accounts, to gain unauthorized access to sensitive application data and backend functions. This impacts all organizations currently running Django-Vue-Lyadmin versions 3.2.12 or older that have not explicitly rotated the default hard-coded secret key.

Recommendation

Prioritized actions for security and development teams:

  • Immediately rotate the SECRET_KEY in backend/application/settings.py to a strong, cryptographically secure, and unique value for all Django-Vue-Lyadmin instances.
  • Review all existing JWT-based sessions to identify potentially unauthorized tokens signed with the default key.
  • Patch or upgrade the environment to a secure configuration as recommended by the vendor documentation.
  • Enable monitoring of authentication logs for unexpected token signatures or account access patterns originating from unauthorized sources.

Immediate actions

Rotate hard-coded SECRET_KEY in backend/application/settings.py

IT Operations 24h

Mitigations

Change default SECRET_KEY

immediate IT Operations

CVE-2026-105392