Search

Find a vulnerability

Search criteria

    8 vulnerabilities by vas3k

    CVE-2026-94040 (GCVE-0-2026-94040)

    Vulnerability from nvd – Published: 2026-09-20 17:00 – Updated: 2026-09-24 12:04
    VLAI
    Title
    vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery
    Summary
    A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 12:04 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    URL Tags
    https://vuldb.com/vuln/407969 vdb-entrytechnical-description
    https://vuldb.com/vuln/407969/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94040 third-party-advisory
    https://vuldb.com/submit/947879 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/187 exploitissue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
    Affected: 0.8.3
    Affected: 0.8.4
    Affected: 0.8.5
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94040",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T12:04:30.461084Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T12:04:54.641Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                },
                {
                  "status": "affected",
                  "version": "0.8.3"
                },
                {
                  "status": "affected",
                  "version": "0.8.4"
                },
                {
                  "status": "affected",
                  "version": "0.8.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "CAPT (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T17:00:06.200Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407969 | vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407969"
            },
            {
              "name": "VDB-407969 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407969/cti"
            },
            {
              "name": "CVE-2026-94040 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94040"
            },
            {
              "name": "Submit #947879 | vas3k TaxHacker 0.8.5 Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/947879"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/187"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T23:10:03.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94040",
        "datePublished": "2026-09-20T17:00:06.200Z",
        "dateReserved": "2026-09-19T21:04:39.135Z",
        "dateUpdated": "2026-09-24T12:04:54.641Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94039 (GCVE-0-2026-94039)

    Vulnerability from nvd – Published: 2026-09-20 16:45 – Updated: 2026-09-21 14:08
    VLAI
    Title
    vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery
    Summary
    A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 14:07 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    URL Tags
    https://vuldb.com/vuln/407968 vdb-entrytechnical-description
    https://vuldb.com/vuln/407968/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94039 third-party-advisory
    https://vuldb.com/submit/947878 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/186 exploitissue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
    Affected: 0.8.3
    Affected: 0.8.4
    Affected: 0.8.5
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94039",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T14:07:53.153639Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T14:08:14.039Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Invoice PDF Renderer"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                },
                {
                  "status": "affected",
                  "version": "0.8.3"
                },
                {
                  "status": "affected",
                  "version": "0.8.4"
                },
                {
                  "status": "affected",
                  "version": "0.8.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "CAPT (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T16:45:13.120Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407968 | vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407968"
            },
            {
              "name": "VDB-407968 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407968/cti"
            },
            {
              "name": "CVE-2026-94039 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94039"
            },
            {
              "name": "Submit #947878 | vas3k TaxHacker 0.8.5 Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/947878"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/186"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T23:09:59.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94039",
        "datePublished": "2026-09-20T16:45:13.120Z",
        "dateReserved": "2026-09-19T21:04:34.756Z",
        "dateUpdated": "2026-09-21T14:08:14.039Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78062 (GCVE-0-2026-78062)

    Vulnerability from nvd – Published: 2026-08-23 04:15 – Updated: 2026-08-27 14:38
    VLAI
    Title
    vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
    Summary
    A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 13:20 UTC
    CWE
    • CWE-798 - Hard-coded Credentials
    • CWE-259 - Use of Hard-coded Password
    References
    URL Tags
    https://vuldb.com/vuln/394302 vdb-entrytechnical-description
    https://vuldb.com/vuln/394302/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-78062 third-party-advisory
    https://vuldb.com/submit/881826 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/147 issue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78062",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T13:20:18.560229Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T14:38:10.867Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "JWT Secret Handler"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "keyblue (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-259",
                  "description": "Use of Hard-coded Password",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-23T04:15:10.545Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-394302 | vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/394302"
            },
            {
              "name": "VDB-394302 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/394302/cti"
            },
            {
              "name": "CVE-2026-78062 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-78062"
            },
            {
              "name": "Submit #881826 | vas3k TaxHacker main Use of Weak Credentials",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/881826"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/147"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-22T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-22T13:01:02.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-78062",
        "datePublished": "2026-08-23T04:15:10.545Z",
        "dateReserved": "2026-08-22T10:55:54.278Z",
        "dateUpdated": "2026-08-27T14:38:10.867Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78061 (GCVE-0-2026-78061)

    Vulnerability from nvd – Published: 2026-08-23 03:45 – Updated: 2026-08-24 18:27
    VLAI
    Title
    vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery
    Summary
    A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-24 18:27 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78061",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-24T18:27:04.738756Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-24T18:27:28.301Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/vas3k/TaxHacker/issues/148"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Email Sync"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "keyblue (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-23T03:45:09.870Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-394301 | vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/394301"
            },
            {
              "name": "VDB-394301 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/394301/cti"
            },
            {
              "name": "CVE-2026-78061 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-78061"
            },
            {
              "name": "Submit #881825 | vas3k TaxHacker main Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/881825"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/148"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/vas3k/TaxHacker/pull/170"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-22T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-22T13:00:56.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-78061",
        "datePublished": "2026-08-23T03:45:09.870Z",
        "dateReserved": "2026-08-22T10:54:25.793Z",
        "dateUpdated": "2026-08-24T18:27:28.301Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94040 (GCVE-0-2026-94040)

    Vulnerability from cvelistv5 – Published: 2026-09-20 17:00 – Updated: 2026-09-24 12:04
    VLAI
    Title
    vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery
    Summary
    A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 12:04 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    URL Tags
    https://vuldb.com/vuln/407969 vdb-entrytechnical-description
    https://vuldb.com/vuln/407969/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94040 third-party-advisory
    https://vuldb.com/submit/947879 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/187 exploitissue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
    Affected: 0.8.3
    Affected: 0.8.4
    Affected: 0.8.5
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94040",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T12:04:30.461084Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T12:04:54.641Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                },
                {
                  "status": "affected",
                  "version": "0.8.3"
                },
                {
                  "status": "affected",
                  "version": "0.8.4"
                },
                {
                  "status": "affected",
                  "version": "0.8.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "CAPT (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T17:00:06.200Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407969 | vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407969"
            },
            {
              "name": "VDB-407969 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407969/cti"
            },
            {
              "name": "CVE-2026-94040 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94040"
            },
            {
              "name": "Submit #947879 | vas3k TaxHacker 0.8.5 Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/947879"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/187"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T23:10:03.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94040",
        "datePublished": "2026-09-20T17:00:06.200Z",
        "dateReserved": "2026-09-19T21:04:39.135Z",
        "dateUpdated": "2026-09-24T12:04:54.641Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94039 (GCVE-0-2026-94039)

    Vulnerability from cvelistv5 – Published: 2026-09-20 16:45 – Updated: 2026-09-21 14:08
    VLAI
    Title
    vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery
    Summary
    A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 14:07 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    URL Tags
    https://vuldb.com/vuln/407968 vdb-entrytechnical-description
    https://vuldb.com/vuln/407968/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94039 third-party-advisory
    https://vuldb.com/submit/947878 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/186 exploitissue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
    Affected: 0.8.3
    Affected: 0.8.4
    Affected: 0.8.5
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94039",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T14:07:53.153639Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T14:08:14.039Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Invoice PDF Renderer"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                },
                {
                  "status": "affected",
                  "version": "0.8.3"
                },
                {
                  "status": "affected",
                  "version": "0.8.4"
                },
                {
                  "status": "affected",
                  "version": "0.8.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "CAPT (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-20T16:45:13.120Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-407968 | vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/407968"
            },
            {
              "name": "VDB-407968 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/407968/cti"
            },
            {
              "name": "CVE-2026-94039 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94039"
            },
            {
              "name": "Submit #947878 | vas3k TaxHacker 0.8.5 Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/947878"
            },
            {
              "tags": [
                "exploit",
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/186"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-19T23:09:59.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94039",
        "datePublished": "2026-09-20T16:45:13.120Z",
        "dateReserved": "2026-09-19T21:04:34.756Z",
        "dateUpdated": "2026-09-21T14:08:14.039Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78062 (GCVE-0-2026-78062)

    Vulnerability from cvelistv5 – Published: 2026-08-23 04:15 – Updated: 2026-08-27 14:38
    VLAI
    Title
    vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
    Summary
    A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 13:20 UTC
    CWE
    • CWE-798 - Hard-coded Credentials
    • CWE-259 - Use of Hard-coded Password
    References
    URL Tags
    https://vuldb.com/vuln/394302 vdb-entrytechnical-description
    https://vuldb.com/vuln/394302/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-78062 third-party-advisory
    https://vuldb.com/submit/881826 third-party-advisory
    https://github.com/vas3k/TaxHacker/issues/147 issue-tracking
    https://github.com/vas3k/TaxHacker/ product
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78062",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T13:20:18.560229Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T14:38:10.867Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "JWT Secret Handler"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "keyblue (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-259",
                  "description": "Use of Hard-coded Password",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-23T04:15:10.545Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-394302 | vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/394302"
            },
            {
              "name": "VDB-394302 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/394302/cti"
            },
            {
              "name": "CVE-2026-78062 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-78062"
            },
            {
              "name": "Submit #881826 | vas3k TaxHacker main Use of Weak Credentials",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/881826"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/147"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-22T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-22T13:01:02.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-78062",
        "datePublished": "2026-08-23T04:15:10.545Z",
        "dateReserved": "2026-08-22T10:55:54.278Z",
        "dateUpdated": "2026-08-27T14:38:10.867Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78061 (GCVE-0-2026-78061)

    Vulnerability from cvelistv5 – Published: 2026-08-23 03:45 – Updated: 2026-08-24 18:27
    VLAI
    Title
    vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery
    Summary
    A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-24 18:27 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    References
    Impacted products
    Vendor Product Version
    vas3k TaxHacker Affected: 0.8.0
    Affected: 0.8.1
    Affected: 0.8.2
        cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78061",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-24T18:27:04.738756Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-24T18:27:28.301Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/vas3k/TaxHacker/issues/148"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Email Sync"
              ],
              "product": "TaxHacker",
              "vendor": "vas3k",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.8.0"
                },
                {
                  "status": "affected",
                  "version": "0.8.1"
                },
                {
                  "status": "affected",
                  "version": "0.8.2"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "keyblue (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-23T03:45:09.870Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-394301 | vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/394301"
            },
            {
              "name": "VDB-394301 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/394301/cti"
            },
            {
              "name": "CVE-2026-78061 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-78061"
            },
            {
              "name": "Submit #881825 | vas3k TaxHacker main Server-Side Request Forgery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/881825"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vas3k/TaxHacker/issues/148"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/vas3k/TaxHacker/pull/170"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vas3k/TaxHacker/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-22T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-22T13:00:56.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-78061",
        "datePublished": "2026-08-23T03:45:09.870Z",
        "dateReserved": "2026-08-22T10:54:25.793Z",
        "dateUpdated": "2026-08-24T18:27:28.301Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }