<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avas3ktaxhacker/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 18:22:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avas3ktaxhacker/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in vas3k TaxHacker via Invoice PDF Renderer</title><link>https://feed.craftedsignal.io/briefs/2026-09-taxhacker-ssrf/</link><pubDate>Sun, 20 Sep 2026 18:22:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-taxhacker-ssrf/</guid><description>A server-side request forgery (SSRF) vulnerability in the TaxHacker Invoice PDF Renderer allows remote attackers to perform unauthorized requests by manipulating the businessLogo argument.</description><content:encoded><![CDATA[<p>A server-side request forgery (SSRF) vulnerability, assigned CVE-2026-94039, has been identified in the TaxHacker application developed by vas3k in versions up to 0.8.5. The flaw is located within the <code>generateInvoicePDF</code> function inside the <code>/apps/invoices/actions.ts</code> file, specifically within the Invoice PDF Renderer component. An unauthenticated remote attacker can trigger the vulnerability by providing a crafted value to the <code>businessLogo</code> argument during the PDF generation process. Successful exploitation allows the application server to perform unauthorized outbound HTTP requests, potentially exposing internal network resources or metadata services. As of the report date, the vulnerability remains unpatched and is publicly disclosed, increasing the likelihood of exploitation attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to bypass network access controls, perform reconnaissance of internal infrastructure, or potentially access sensitive internal metadata and services reachable by the server. This vulnerability is applicable to any deployment of TaxHacker up to version 0.8.5.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor web access logs for suspicious input patterns directed at the invoice generation endpoint. Due to the lack of a vendor patch, network-level egress filtering is the most effective mitigation strategy for internal resources.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>web-application</category><category>vulnerability</category></item></channel></rss>