PatchSiren

vas3k CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vas3k CVE published 2026-09-20

CVE-2026-94040

A server-side request forgery vulnerability has been identified in vas3k TaxHacker up to version 0.8.5. The issue affects the testLLMProviderAction function in the file app/(app)/apps/settings/actions.ts. This function can be manipulated through the provider, apiKey, model, and baseUrl arguments, potentially allowing for unauthorized requests to be made from the server. The vulnerability has been publicly [truncated]

MEDIUM vas3k CVE published 2026-09-20

CVE-2026-94039

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. The function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer is affected by server-side request forgery when manipulating the argument businessLogo. The attack can be carried out remotely and a public exploit exists. This vulnerability allows for server-side request forgery, which can lead to potent [truncated]