CVE-2026-94040

Summary

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
vas3kTaxHacker0.8.0affected
vas3kTaxHacker0.8.1affected
vas3kTaxHacker0.8.2affected
vas3kTaxHacker0.8.3affected
vas3kTaxHacker0.8.4affected
vas3kTaxHacker0.8.5affected

Weaknesses

  • CWE-918: Server-Side Request Forgery

References