CVE-2026-108753
Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose
CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
0th
Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
| CWE | CWE-798 |
| Vendor | agnaistic |
| Product | agnai |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for agnaistic agnai
Be the first to know when new critical vulnerabilities affecting agnaistic agnai are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Affected Versions
agnaistic / agnai
0 โค 1.0.555
References
hackmd.io: https://hackmd.io/@haind/agnai-selfhost-compose-hardcoded-admin-jwt-secret github.com: https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d2352681186/self-host.docker-compose.yml#L18-L26 github.com: https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d2352681186/README.md#L75-L82 github.com: https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d2352681186/srv/api/auth.ts#L11-L14 github.com: https://github.com/agnaistic/agnai vulncheck.com: https://www.vulncheck.com/advisories/agnaistic-agnai-through-1.0.555-hard-coded-credentials-in-self-host-docker-compose
Credits
HaiND from the Post and Telecommunication Institute of Technology