Executive brief
Cognee is a platform for managing AI knowledge and LLM operations. This vulnerability allows any unauthenticated user to register a basic account and modify the global LLM configuration settings, which are used across all users and operations on the system. An attacker can redirect all AI language model queries to an attacker-controlled server, enabling them to intercept and steal sensitive data such as user prompts, uploaded documents, extracted entities, and knowledge graphs from all users on the instance.
Technical details
This vulnerability is rooted in CWE-306 (Missing Authentication for Critical Function), where the API settings endpoint fails to enforce role-based access control for critical configuration changes. The vulnerable component is the `/api/v1/settings` endpoint, which modifies process-wide singleton configuration that affects all LLM operations system-wide. An attacker with a self-registered (non-privileged) account can invoke this endpoint without authentication checks, overwriting the LLM provider URL to point to an attacker-controlled server. The attack vector is network-based with no required privileges or user interaction. The root cause is the absence of admin/superuser privilege validation before allowing configuration changes. Once exploited, all LLM operations on the instance—including prompt processing, document analysis, and entity extraction—are redirected through the attacker's endpoint, enabling full interception of sensitive data. The vulnerability was patched in version 1.5.0, with notable fixes in commits d10b1b7, 10971db, and ebcf824.
Affected products
- topoteretes cognee < 1.5.0
Timeline
- 2026-07-07: disclosed
- 2026-07-07: patched: Published to NVD; patched in version 1.5.0