A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-259",
"CWE-798"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78062.json"
}{
"extracted_events": [
{
"introduced": "0.8.0"
},
{
"last_affected": "0.8.0"
},
{
"introduced": "0.8.1"
},
{
"last_affected": "0.8.1"
},
{
"introduced": "0.8.2"
},
{
"last_affected": "0.8.2"
}
],
"source": "AFFECTED_FIELD"
}