Product
Peppermint versions through 0.5.5 contain a hardcoded JWT signing secret in docker-compose.yml, allowing unauthenticated attackers to forge arbitrary session tokens.