PT-2026-79757 · Vas3K · Taxhacker
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
vas3k TaxHacker versions prior to 0.8.3
Description
An issue exists in the JWT Secret Handler component within the
envSchema.parse() function located in the lib/config.ts file. Remote manipulation of the BETTER AUTH SECRET argument can lead to the use of hard-coded credentials.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict the use of the
BETTER AUTH SECRET argument in the envSchema.parse() function.Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Taxhacker