← Back to overview

A vulnerability was identified in vas3k TaxHacker up to version 0.8.2 involving hard-coded credentials. The affected component is the JWT Secret Handler, specifically the envSchema.parse function in lib/config.ts. The vulnerability arises from the manipulation of the BETTER_AUTH_SECRET argument, which results in hard-coded credentials being used. The attack can be initiated remotely, making it a significant security risk. The project maintainer was notified via an issue report but has not yet responded or released a patch. Hard-coded credentials can allow attackers to bypass authentication mechanisms and gain unauthorized access to systems. The vulnerability is tracked under CVE-2026-78062 and has been reported on VulDB as well as GitHub.

Affected products

  • vas3k TaxHacker up to 0.8.2

Related CVE's

  • CVE-2026-78062

Categories

  • Identity & Access
  • Web Technologies