CVE-2026-94040

Source
https://cve.org/CVERecord?id=CVE-2026-94040
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94040.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94040
Published
2026-09-20T17:00:06Z
Modified
2026-09-22T03:45:53Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery
Details

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94040.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "0.8.3"
                },
                {
                    "last_affected":  "0.8.3"
                },
                {
                    "introduced":  "0.8.4"
                },
                {
                    "last_affected":  "0.8.4"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/vas3k/taxhacker

Affected ranges

Type
GIT
Repo
https://github.com/vas3k/taxhacker
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.8.0"
        },
        {
            "last_affected":  "0.8.0"
        },
        {
            "introduced":  "0.8.1"
        },
        {
            "last_affected":  "0.8.1"
        },
        {
            "introduced":  "0.8.2"
        },
        {
            "last_affected":  "0.8.2"
        },
        {
            "introduced":  "0.8.5"
        },
        {
            "last_affected":  "0.8.5"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

0.*
0.8.0
0.8.1
0.8.2
0.8.5
v0.*
v0.8.0
v0.8.1
v0.8.2
v0.8.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94040.json"