Impact
The vulnerability exposes a fixed admin password and a public JWT secret in the self‑host docker‑compose.yml file of Agnaistic agnai. An unauthenticated attacker can log in as administrator or forge a token with admin privileges, gaining full control over the server. This allows resetting arbitrary user passwords, modifying configuration, and potentially compromising confidentiality, integrity and availability.
Affected Systems
Agnaistic agnai versions up to and including 1.0.555 contain hard‑coded credentials in the docker‑compose.yml file. Any deployment that uses the default configuration or older releases is susceptible unless the user replaces the hard‑coded password and JWT secret with unique values before deployment.
Risk and Exploitability
The CVSS score of 9.3 denotes critical severity. EPSS is not available but the attack is straightforward: an attacker with network access to the deployed service can exploit the static credentials without complex steps. The vulnerability is not listed in CISA KEV, yet the combination of easy exploitation and full administrative takeover yields a high risk.
OpenCVE Enrichment