PT-2026-79757 · Vas3K · Taxhacker

·

CVE-2026-78062

·

Published

2026-08-23

·

Updated

2026-08-23

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vas3k TaxHacker versions prior to 0.8.3
Description An issue exists in the JWT Secret Handler component within the envSchema.parse() function located in the lib/config.ts file. Remote manipulation of the BETTER AUTH SECRET argument can lead to the use of hard-coded credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, restrict the use of the BETTER AUTH SECRET argument in the envSchema.parse() function.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78062

Affected Products

Taxhacker