Skip to content
Threat Feed
critical advisory

Hardcoded JWT Signing Secret in Peppermint

Peppermint versions through 0.5.5 contain a hardcoded JWT signing secret in docker-compose.yml, allowing unauthenticated attackers to forge arbitrary session tokens.

CVE search metadata

CVE search record: CVE-2026-85391. Severity: critical. CVSS: 9.8. KEV: no. Product: Peppermint (<= 0.5.5). Brief: Hardcoded JWT Signing Secret in Peppermint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-peppermint-jwt-secret/

Peppermint versions up to and including 0.5.5 suffer from a critical security vulnerability involving a hardcoded JWT signing secret located in the project's docker-compose.yml file. By design, this secret is intended to sign session tokens for authenticating users. Because the secret is public and hardcoded within the repository, any unauthenticated attacker can retrieve it and use it to sign and forge valid JWT session tokens for any account within the target instance. This flaw allows unauthorized access to protected endpoints and complete account takeover, effectively bypassing authentication mechanisms. This impact is significant as it provides high-privileged access without requiring credentials. Organizations deploying Peppermint 0.5.5 or earlier should prioritize rotating this secret and upgrading to a remediated version once available.

Impact

The vulnerability allows for complete authentication bypass and account takeover on any Peppermint instance using the default docker-compose configuration. An attacker can impersonate any user, including administrative accounts, to gain unauthorized access to sensitive application data and functions.

Recommendation

Prioritize the following actions to secure Peppermint environments:

  • Audit the docker-compose.yml file for the presence of the hardcoded secret and revoke it immediately.
  • Implement environment variable management to inject secrets at runtime rather than hardcoding them in configuration files.
  • Monitor logs for unusual authentication patterns or tokens signed with the default secret if it cannot be immediately rotated.
  • Upgrade Peppermint to a patched version once released by the maintainers.

Immediate actions

Rotate the JWT signing secret and update docker-compose.yml to use environment-injected secrets.

IT Operations 24h

Mitigations

Remove the hardcoded secret from the environment and rotate all existing session tokens.

immediate IT Operations

CVE-2026-85391