Vulnerability  ·  2026-09-29

refly-ai: hard-coded JWT signing credentials in app.config.ts allow auth bypass

VulnerabilityMedium impactGlobalCVE-2026-101052
A security analysis of refly, an open-source AI coding/agent workspace, found JWT signing credentials hard-coded in the API config module, letting remote attackers forge authenticated tokens. Despite contact, the vendor had not responded and no remediation was published at disclosure time.
Refly is an AI-agent workspace where users expose code generation, repo access and LLM API credentials; a hard-coded signing secret that lets a remote attacker mint valid session tokens defeats the authentication boundary guarding AI tooling and any connected LLM/provider keys.
The JWT Token Handler in app.config.ts ships hard-coded credentials used to sign/verify session tokens; a remote attacker can use the known secret to mint tokens that pass validation and gain access to the application's authenticated surfaces.
refly-ai refly up to and including 1.1.0 (apps/api/src/modules/config/app.config.ts JWT handler)
No vendor fix as of publication; restrict network exposure, rotate any derived secrets, and monitor for forged-token activity until the vendor responds.
NVD CVE-2026-101052Disclosure (Hard-coded.md)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →