A vulnerability was determined in vas3k TaxHacker up to 0.8.2. (CVE-2026-78061)
A server-side request forgery (SSRF) vulnerability exists in vas3k TaxHacker up to version 0.8.2 in the buildImapConfig function of the Email Sync component. This vulnerability allows remote attackers to manipulate the host and port arguments, potentially causing the server to make unintended requests. A fix has been developed but is pending acceptance in a pull request. The vulnerability has a CVSS 3.1 score of 6.3, indicating a medium severity level.
AI Analysis
Technical Summary
The vulnerability in vas3k TaxHacker (up to 0.8.2) affects the buildImapConfig function within lib/email-sync/imap-client.ts, part of the Email Sync component. By manipulating the host and port arguments, an attacker can trigger server-side request forgery (CWE-918), causing the server to send crafted requests to arbitrary destinations. The vulnerability is remotely exploitable without user interaction and requires low privileges. A patch is available as a pull request but has not yet been merged or officially released.
Potential Impact
Successful exploitation allows an attacker to induce the server to make arbitrary requests, potentially accessing internal resources or services not otherwise reachable. This can lead to information disclosure, integrity loss, or availability impact depending on the target of the forged requests. The CVSS score of 6.3 reflects moderate confidentiality, integrity, and availability impacts.
Mitigation Recommendations
A fix for this vulnerability exists in a pending pull request but has not yet been officially released. Users should monitor the project's repository for the acceptance and release of this patch. Until then, consider restricting network access or applying other environment-specific mitigations to limit the impact of SSRF attacks.
A vulnerability was determined in vas3k TaxHacker up to 0.8.2. (CVE-2026-78061)
Description
A server-side request forgery (SSRF) vulnerability exists in vas3k TaxHacker up to version 0.8.2 in the buildImapConfig function of the Email Sync component. This vulnerability allows remote attackers to manipulate the host and port arguments, potentially causing the server to make unintended requests. A fix has been developed but is pending acceptance in a pull request. The vulnerability has a CVSS 3.1 score of 6.3, indicating a medium severity level.
CVSS v3.1
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in vas3k TaxHacker (up to 0.8.2) affects the buildImapConfig function within lib/email-sync/imap-client.ts, part of the Email Sync component. By manipulating the host and port arguments, an attacker can trigger server-side request forgery (CWE-918), causing the server to send crafted requests to arbitrary destinations. The vulnerability is remotely exploitable without user interaction and requires low privileges. A patch is available as a pull request but has not yet been merged or officially released.
Potential Impact
Successful exploitation allows an attacker to induce the server to make arbitrary requests, potentially accessing internal resources or services not otherwise reachable. This can lead to information disclosure, integrity loss, or availability impact depending on the target of the forged requests. The CVSS score of 6.3 reflects moderate confidentiality, integrity, and availability impacts.
Mitigation Recommendations
A fix for this vulnerability exists in a pending pull request but has not yet been officially released. Users should monitor the project's repository for the acceptance and release of this patch. Until then, consider restricting network access or applying other environment-specific mitigations to limit the impact of SSRF attacks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hrrq-qh5p-23c2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-78061"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a8af9a0acd9273b49f32e6d
Added to database: 08/23/2026, 13:46:08 UTC
Last enriched: 08/23/2026, 13:47:57 UTC
Last updated: 08/24/2026, 03:51:58 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.