Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85391: Peppermint up to version 0.5.5 lets attackers fake login tokens
CVE-2026-85391 · published today
Summary
The container setup file used by Peppermint versions up to 0.5.5 includes a secret key that is publicly visible. Because of this, someone without an account can create a valid login token and access any user’s data or functions. Update to the newest Peppermint release or replace the secret key in the setup file and restart the service.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| peppermint-lab | peppermint | <= 0.5.5 |
Original advisory text
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published...
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.
References
- https://github.com/Peppermint-Lab/peppermint
- https://github.com/Peppermint-Lab/peppermint/blob/0.5.5/apps/api/src/lib/jwt.ts
- https://github.com/Peppermint-Lab/peppermint/blob/0.5.5/docker-compose.yml
- https://github.com/Peppermint-Lab/peppermint/issues/528
- https://www.vulncheck.com/advisories/peppermint-through-0.5.5-use-of-hard-coded-...
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta