CVE-2026-78061: VAS3K Taxhacker
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Affected products
- VAS3K Taxhacker: version 0.8.0 only; version 0.8.1 only; version 0.8.2 only
Published 2026-08-23. Last modified 2026-08-24.