{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/vas3k/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78062"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TaxHacker (0.8.2)"],"_cs_severities":["high"],"_cs_tags":["cve","hardcoded-credentials","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["vas3k"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-78062) has been identified in the TaxHacker project, specifically within versions up to 0.8.2. The vulnerability resides in the JWT Secret Handler component, located in the lib/config.ts file. The envSchema.parse function improperly handles the BETTER_AUTH_SECRET argument, resulting in the usage of hard-coded credentials for authentication secrets. An attacker can exploit this remotely to bypass authentication mechanisms or forge JWTs. The issue was disclosed via a GitHub issue report, but as of the publication date, the maintainers have not issued a patch. Defenders should treat this as a high-risk exposure if TaxHacker is deployed in production environments where JWT security is critical.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to gain access to hard-coded secrets. In the context of a JWT Secret Handler, this typically leads to the ability to forge, sign, or decrypt JSON Web Tokens, potentially resulting in unauthorized administrative access, privilege escalation, or data exfiltration across systems relying on these tokens for identity verification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all deployments of TaxHacker to confirm the version is 0.8.2 or earlier.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to the TaxHacker application if it cannot be immediately patched or removed.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for anomalous requests to endpoints that handle authentication or token generation until the vendor releases a fix.\u003c/li\u003e\n\u003cli\u003eCheck the project repository (\u003ca href=\"https://github.com/vas3k/TaxHacker/issues/147\"\u003ehttps://github.com/vas3k/TaxHacker/issues/147\u003c/a\u003e) for updates on a vendor-provided fix or manual workarounds.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-23T05:35:12Z","date_published":"2026-08-23T05:35:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-taxhacker-hardcoded-creds/","summary":"TaxHacker versions 0.8.2 and earlier contain a hard-coded credential vulnerability in the JWT Secret Handler, allowing potential remote exploitation via the BETTER_AUTH_SECRET argument.","title":"Hard-coded Credential Vulnerability in TaxHacker","url":"https://feed.craftedsignal.io/briefs/2026-08-taxhacker-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Vas3k","version":"https://jsonfeed.org/version/1.1"}