Ghostwire

CVE-2026-78062: A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of...

HIGH CVSS 7.3 Exploit Available

Published: August 23, 2026 | Last Modified: August 23, 2026

Description

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References