Product
The Django-Vue-Lyadmin project up to version 3.2.12 contains a hard-coded SECRET_KEY in backend/application/settings.py, allowing remote attackers to forge JWT tokens and gain unauthorized access.