CVE-2026-94039

Source
https://cve.org/CVERecord?id=CVE-2026-94039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94039
Published
2026-09-20T16:45:13Z
Modified
2026-09-22T03:45:54Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery
Details

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94039.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "0.8.3"
                },
                {
                    "last_affected":  "0.8.3"
                },
                {
                    "introduced":  "0.8.4"
                },
                {
                    "last_affected":  "0.8.4"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/vas3k/taxhacker

Affected ranges

Type
GIT
Repo
https://github.com/vas3k/taxhacker
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.8.0"
        },
        {
            "last_affected":  "0.8.0"
        },
        {
            "introduced":  "0.8.1"
        },
        {
            "last_affected":  "0.8.1"
        },
        {
            "introduced":  "0.8.2"
        },
        {
            "last_affected":  "0.8.2"
        },
        {
            "introduced":  "0.8.5"
        },
        {
            "last_affected":  "0.8.5"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

0.*
0.8.0
0.8.1
0.8.2
0.8.5
v0.*
v0.8.0
v0.8.1
v0.8.2
v0.8.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94039.json"