CyberRota Analysis
AI-GeneratedA vulnerability in the JWT Secret Handler of vas3k TaxHacker versions up to 0.8.2 allows remote attackers to exploit the envSchema.parse function, leading to the exposure of hard-coded credentials via manipulation of the BETTER_AUTH_SECRET argument. This high-severity issue poses a significant risk to users of the affected software, particularly those handling sensitive data or financial transactions. Organizations using this version should prioritize immediate remediation to mitigate potential unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.