CVE-2026-78062 | vas3k TaxHacker up to 0.8.2 JWT Secret lib/config.ts envSchema.parse BETTER_AUTH_SECRET hard-coded credentials

SecurityVulns

A vulnerability was found in vas3k TaxHacker up to 0.8.2. It has been classified as critical. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials.

This vulnerability is documented as CVE-2026-78062. The attack can be initiated remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More