{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avas3ktaxhacker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94039"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TaxHacker (\u003c= 0.8.5)"],"_cs_severities":["high"],"_cs_tags":["ssrf","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["vas3k"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability, assigned CVE-2026-94039, has been identified in the TaxHacker application developed by vas3k in versions up to 0.8.5. The flaw is located within the \u003ccode\u003egenerateInvoicePDF\u003c/code\u003e function inside the \u003ccode\u003e/apps/invoices/actions.ts\u003c/code\u003e file, specifically within the Invoice PDF Renderer component. An unauthenticated remote attacker can trigger the vulnerability by providing a crafted value to the \u003ccode\u003ebusinessLogo\u003c/code\u003e argument during the PDF generation process. Successful exploitation allows the application server to perform unauthorized outbound HTTP requests, potentially exposing internal network resources or metadata services. As of the report date, the vulnerability remains unpatched and is publicly disclosed, increasing the likelihood of exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to bypass network access controls, perform reconnaissance of internal infrastructure, or potentially access sensitive internal metadata and services reachable by the server. This vulnerability is applicable to any deployment of TaxHacker up to version 0.8.5.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor web access logs for suspicious input patterns directed at the invoice generation endpoint. Due to the lack of a vendor patch, network-level egress filtering is the most effective mitigation strategy for internal resources.\u003c/p\u003e\n","date_modified":"2026-09-20T18:22:55Z","date_published":"2026-09-20T18:22:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-taxhacker-ssrf/","summary":"A server-side request forgery (SSRF) vulnerability in the TaxHacker Invoice PDF Renderer allows remote attackers to perform unauthorized requests by manipulating the businessLogo argument.","title":"SSRF Vulnerability in vas3k TaxHacker via Invoice PDF Renderer","url":"https://feed.craftedsignal.io/briefs/2026-09-taxhacker-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}