Skip to content
cogneeGHSA-49f7-whx5-4256

Cognee allows non-superusers to overwrite global LLM configuration

Critical9.1CVE-2026-58473 · Published Jul 7, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
cognee
PyPI
< 1.5.01.5.0
Details and references

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint by exploiting the process-wide singleton configuration cache, enabling exfiltration of prompts, uploaded documents, extracted entities, and knowledge graph content from all users.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-306
Also known as
CVE-2026-58473, PYSEC-2026-3816

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.