All 4 CVE vulnerabilities found in Peppermint, with AI-generated Chinese analysis, references, and POCs.
Vendor: Peppermint Lab
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-85391 | Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml CWE-798 | 9.8 | Critical | 2026-09-03 |
| CVE-2026-85392 | Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint CWE-639 | 4.3 | Medium | 2026-09-03 |
| CVE-2026-72561 | Peppermint Lab Peppermint - Broken Access Control CWE-284 | 8.8 | High | 2026-08-11 |
| CVE-2026-72555 | Peppermint Lab Peppermint - Broken Access Control CWE-284 | 8.1 | High | 2026-08-11 |
All 4 known CVE vulnerabilities affecting Peppermint with full Chinese analysis, references, and POCs where available.