PT-2026-95982 · Vas3K · Taxhacker

·

CVE-2026-94040

·

Published

2026-09-20

·

Updated

2026-09-24

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions vas3k TaxHacker versions prior to 0.8.6
Description A remote server-side request forgery (SSRF) exists in the testLLMProviderAction() function within the app/(app)/apps/settings/actions.ts file. This occurs when the provider, apiKey, model, or baseUrl arguments are manipulated, allowing an attacker to induce the server to make unauthorized requests.
Recommendations As a temporary workaround, restrict access to the testLLMProviderAction() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94040

Affected Products

Taxhacker