Hardcoded JWT Signing Secret in Peppermint Product by Peppermint Lab
CVE-2026-85391

9.3CRITICAL

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85391?

The Peppermint product version 0.5.5 contains a security flaw due to a hardcoded JSON Web Token (JWT) signing secret found in the docker-compose.yml file. This weakness enables unauthenticated attackers to generate valid session tokens for any user account, thereby gaining unauthorized access to protected resources and endpoints. Exploiting this vulnerability allows potential attackers to bypass normal authentication mechanisms, posing a significant risk to the system's integrity and user security.

Affected Version(s)

peppermint 0 <= 0.5.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.