A server-side request forgery vulnerability has been identified in vas3k TaxHacker up to version 0.8.5. The issue affects the testLLMProviderAction function in the file app/(app)/apps/settings/actions.ts. This function can be manipulated through the provider, apiKey, model, and baseUrl arguments, potentially allowing for unauthorized requests to be made from the server. The vulnerability has been publicly [truncated]
A vulnerability was detected in vas3k TaxHacker up to 0.8.5. The function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer is affected by server-side request forgery when manipulating the argument businessLogo. The attack can be carried out remotely and a public exploit exists. This vulnerability allows for server-side request forgery, which can lead to potent [truncated]