Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-78062: TaxHacker exposes JWT secret through hard‑coded credentials

CVE-2026-78062 · published 12 days ago
Summary

The TaxHacker application (versions up to 0.8.2) stores its authentication secret in the code instead of a secure location. This makes it possible for an attacker to retrieve the secret and impersonate users or gain unauthorized access. Update the software to a patched version or reconfigure the application to keep the secret in a protected environment variable.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
vas3k taxhacker 0.8.0
Original advisory text
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation o...
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity
5.5 Medium
CVSS 4.0: 8.4 (OSV)
CVSS 3.1: 7.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
CWE-259Use of Hard-coded Password
Timeline
Published23 Aug 2026
Updated29 Aug 2026
First seen23 Aug 2026
Sources
CVE-2026-78062 · MITRE
Monitor software like this
Free during beta