CVE-2026-78062

Summary

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
vas3kTaxHacker0.8.0affected
vas3kTaxHacker0.8.1affected
vas3kTaxHacker0.8.2affected

Weaknesses

  • CWE-798: Hard-coded Credentials
  • CWE-259: Use of Hard-coded Password

References