VYPR

agnai

by Agnaistic

CVEs (1)

  • CVE-2026-108753CriOct 11, 2026
    risk 0.61cvss 9.4epss —

    Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users,…