MEDIUM
refly-ai refly JWT Token app.config.ts hard-coded credentials
Published Sep 28, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.45%
Description
A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version 1.1.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/DReazer/CV3/blob/main/refly/Hard-coded.md exploit
- https://vuldb.com/cve/CVE-2026-101052 third-party-advisory
- https://vuldb.com/submit/927328 third-party-advisory
- https://vuldb.com/vuln/410910 vdb-entrytechnical-description
- https://vuldb.com/vuln/410910/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/DReazer/CV3/blob/main/refly/Hard-coded.md | exploit | |
| https://vuldb.com/cve/CVE-2026-101052 | third-party-advisory | |
| https://vuldb.com/submit/927328 | third-party-advisory | |
| https://vuldb.com/vuln/410910 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/410910/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 28, 2026
Updated Sep 28, 2026
Reserved Sep 27, 2026
Link CVE-2026-101052
CISA Vulnrichment
Updated Sep 28, 2026