{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/peppermint/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:peppermint:peppermint:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85391"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Peppermint (\u003c= 0.5.5)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Peppermint"],"content_html":"\u003cp\u003ePeppermint versions up to and including 0.5.5 suffer from a critical security vulnerability involving a hardcoded JWT signing secret located in the project's docker-compose.yml file. By design, this secret is intended to sign session tokens for authenticating users. Because the secret is public and hardcoded within the repository, any unauthenticated attacker can retrieve it and use it to sign and forge valid JWT session tokens for any account within the target instance. This flaw allows unauthorized access to protected endpoints and complete account takeover, effectively bypassing authentication mechanisms. This impact is significant as it provides high-privileged access without requiring credentials. Organizations deploying Peppermint 0.5.5 or earlier should prioritize rotating this secret and upgrading to a remediated version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete authentication bypass and account takeover on any Peppermint instance using the default docker-compose configuration. An attacker can impersonate any user, including administrative accounts, to gain unauthorized access to sensitive application data and functions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure Peppermint environments:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit the docker-compose.yml file for the presence of the hardcoded secret and revoke it immediately.\u003c/li\u003e\n\u003cli\u003eImplement environment variable management to inject secrets at runtime rather than hardcoding them in configuration files.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual authentication patterns or tokens signed with the default secret if it cannot be immediately rotated.\u003c/li\u003e\n\u003cli\u003eUpgrade Peppermint to a patched version once released by the maintainers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T19:22:28Z","date_published":"2026-09-03T19:22:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-peppermint-jwt-secret/","summary":"Peppermint versions through 0.5.5 contain a hardcoded JWT signing secret in docker-compose.yml, allowing unauthenticated attackers to forge arbitrary session tokens.","title":"Hardcoded JWT Signing Secret in Peppermint","url":"https://feed.craftedsignal.io/briefs/2026-09-peppermint-jwt-secret/"}],"language":"en","title":"CraftedSignal Threat Feed - Peppermint","version":"https://jsonfeed.org/version/1.1"}