Description
A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Update
AI Analysis

Impact

A manipulation of the businessLogo argument in TaxHacker’s generateInvoicePDF function allows an attacker to provoke the server into making a request to an arbitrary URL. The vulnerability is a classic server‑side request forgery (CWE‑918) that can be exploited remotely and may expose internal network resources or leaks confidential data. While it does not directly execute code, the compromised ability to contact internal services can lead to further compromise or data exfiltration.

Affected Systems

The flaw exists in vas3k:TaxHacker up to and including version 0.8.5. No later version is known to contain the fix; administrators should verify the installed release and consider a later version if available.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity with potential for moderate impact. EPSS information is not available, so the likelihood of exploitation remains uncertain, but the public nature of the exploit and lack of vendor responsiveness raise concern. The vulnerability is not listed in CISA KEV, yet remote attackers can trigger it without authentication, making it highly actionable from a defensive standpoint.

Generated by OpenCVE AI on September 20, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest TaxHacker release that addresses the SSRF in generateInvoicePDF.
  • Modify the businessLogo parameter handling to restrict URLs to a whitelist of trusted domains or disallow external URLs entirely.
  • Deploy network segmentation and firewall rules that block the application’s outbound traffic to internal or sensitive services, thereby limiting the impact of any SSRF attempt.

Generated by OpenCVE AI on September 20, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery
First Time appeared Vas3k
Vas3k taxhacker
Weaknesses CWE-918
CPEs cpe:2.3:a:vas3k:taxhacker:*:*:*:*:*:*:*:*
Vendors & Products Vas3k
Vas3k taxhacker
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T14:08:14.039Z

Reserved: 2026-09-19T21:04:34.756Z

Link: CVE-2026-94039

cve-icon Vulnrichment

Updated: 2026-09-21T14:08:03.585Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T17:16:52.557

Modified: 2026-09-21T15:17:37.837

Link: CVE-2026-94039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)