CVE-2026-105392: Lybbn Django-Vue-Lyadmin

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."

Affected products

  • Lybbn Django-Vue-Lyadmin: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.2.5 only; …

Published 2026-10-05. Last modified 2026-10-06.