[CVE-2026-78062] A vulnerability was identified in vas3k TaxHacker up to 0.8.

CVE-2026-78062 | CVSS: 7.3 | 严重级别: HIGH

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

参考链接:
https://github.com/vas3k/TaxHacker/
https://github.com/vas3k/TaxHacker/issues/147
https://vuldb.com/cve/CVE-2026-78062

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部