CVE-2026-78061

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-23 04:17

Updated : 2026-08-24 19:17


NVD link : CVE-2026-78061

Mitre link : CVE-2026-78061

CVE.ORG link : CVE-2026-78061


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)