Product
TaxHacker versions 0.8.2 and earlier contain a hard-coded credential vulnerability in the JWT Secret Handler, allowing potential remote exploitation via the BETTER_AUTH_SECRET argument.