Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Keyblue

#20355of 56,326
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-79755
6.5
2026-08-23
Vas3K · Taxhacker · CVE-2026-78061
**Name of the Vulnerable Software and Affected Versions** vas3k TaxHacker versions prior to 0.8.3 **Description** In the Email Sync component, the `buildImapConfig()` function within the `lib/email-sync/imap-client.ts` file is susceptible to server-side request forgery (SSRF), a flaw that allows an attacker to induce the server to make requests to an unintended location. This can be triggered remotely by manipulating the `host` and `port` arguments. **Recommendations** As a temporary workaround, restrict the use of the `buildImapConfig()` function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-79757
7.5
2026-08-23
Vas3K · Taxhacker · CVE-2026-78062
**Name of the Vulnerable Software and Affected Versions** vas3k TaxHacker versions prior to 0.8.3 **Description** An issue exists in the JWT Secret Handler component within the `envSchema.parse()` function located in the `lib/config.ts` file. Remote manipulation of the `BETTER AUTH SECRET` argument can lead to the use of hard-coded credentials. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, restrict the use of the `BETTER AUTH SECRET` argument in the `envSchema.parse()` function.