Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-78062: TaxHacker exposes JWT secret through hard‑coded credentials
CVE-2026-78062 · published 12 days ago
Summary
The TaxHacker application (versions up to 0.8.2) stores its authentication secret in the code instead of a secure location. This makes it possible for an attacker to retrieve the secret and impersonate users or gain unauthorized access. Update the software to a patched version or reconfigure the application to keep the secret in a protected environment variable.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vas3k | taxhacker | 0.8.0 |
Original advisory text
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation o...
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
References
- https://vuldb.com/vuln/394302 vdb-entry technical-description
- https://vuldb.com/vuln/394302/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-78062 third-party-advisory
- https://vuldb.com/submit/881826 third-party-advisory
- https://github.com/vas3k/TaxHacker/issues/147 issue-tracking
- https://github.com/vas3k/TaxHacker/ product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78062... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-78062 Vendor Advisory
Severity
5.5
Medium
CVSS 4.0: 8.4 (OSV)
CVSS 3.1: 7.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
CWE-259Use of Hard-coded Password
Timeline
Published23 Aug 2026
Updated29 Aug 2026
First seen23 Aug 2026
Monitor software like this
Free during beta