PatchSiren

agnaistic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL agnaistic CVE published 2026-10-11

CVE-2026-108753

CVE-2026-108753 is a critical vulnerability in Agnaistic agnai through version 1.0.555, where self-hosted Docker Compose files contain hard-coded credentials. This allows unauthenticated attackers to log in as admin or impersonate users by generating their own JWT with admin privileges. The vulnerability exists in the self-host.docker-compose.yml file, where a fixed admin password and public JWT secret ar [truncated]