Vas3K · Taxhacker · CVE-2026-94040
**Name of the Vulnerable Software and Affected Versions**
vas3k TaxHacker versions prior to 0.8.6
**Description**
A remote server-side request forgery (SSRF) exists in the `testLLMProviderAction()` function within the `app/(app)/apps/settings/actions.ts` file. This occurs when the `provider`, `apiKey`, `model`, or `baseUrl` arguments are manipulated, allowing an attacker to induce the server to make unauthorized requests.
**Recommendations**
As a temporary workaround, restrict access to the `testLLMProviderAction()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.