Hardcoded JWT Signing Secret in Peppermint Product by Peppermint Lab
CVE-2026-85391
9.3CRITICAL
What is CVE-2026-85391?
The Peppermint product version 0.5.5 contains a security flaw due to a hardcoded JSON Web Token (JWT) signing secret found in the docker-compose.yml file. This weakness enables unauthenticated attackers to generate valid session tokens for any user account, thereby gaining unauthorized access to protected resources and endpoints. Exploiting this vulnerability allows potential attackers to bypass normal authentication mechanisms, posing a significant risk to the system's integrity and user security.
Affected Version(s)
peppermint 0 <= 0.5.5
