CVE-2026-101052 Details
Description
A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Refly AI's Refly application, specifically in versions through 1.1.0, within the JWT Token Handler component. The issue arises from a hard-coded default JWT secret in the application's configuration file, which can lead to session forgery. This vulnerability allows an unauthenticated attacker to forge access tokens and impersonate users by calling authenticated APIs on their behalf. The vulnerability can be exploited remotely, and the issue has been publicly disclosed.
Users are advised to set a secure JWT secret before deploying the application. The secret should be at least 32 bytes long. After updating the secret, existing tokens should be invalidated to prevent unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DReazer/CV3/blob/main/refly/Hard-coded.md | [email protected] | ExploitRemedyTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-101052 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/927328 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410910 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410910/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Refly AI Refly | 1.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion