CVE-2026-94040 | vas3k TaxHacker up to 0.8.5 actions.ts testLLMProviderAction provider/apiKey/model/baseUrl server-side request forgery (Issue 187)
A vulnerability categorized as problematic has been discovered in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of the argument provider/apiKey/model/baseUrl can lead to server-side request forgery.
This vulnerability appears as CVE-2026-94040. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More