Server-Side Request Forgery Vulnerability in vas3k TaxHacker Email Sync Component
CVE-2026-78061
5.3MEDIUM
What is CVE-2026-78061?
A vulnerability is present in the vas3k TaxHacker application, specifically within the Email Sync component. The issue pertains to the buildImapConfig function located in the imap-client.ts file. An attacker can exploit this vulnerability by manipulating the host and port parameters, leading to a potential server-side request forgery. This attack can be conducted remotely, potentially allowing unauthorized interaction with internal services that should not be exposed. A patch for this vulnerability is currently in the review process.
Affected Version(s)
TaxHacker 0.8.0
TaxHacker 0.8.1
TaxHacker 0.8.2
