CVE-2026-78062: VAS3K Taxhacker
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
- VAS3K Taxhacker: version 0.8.0 only; version 0.8.1 only; version 0.8.2 only
Published 2026-08-23. Last modified 2026-08-27.